Vulnerability Description
When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could modify this data in a way that affects the operation of the cluster.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Geode | >= 1.0.0, <= 1.8.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/108870Third Party Advisory
- https://lists.apache.org/thread.html/311505e7b7a045aaa246f0a1935703acacf41b95462
- http://www.securityfocus.com/bid/108870Third Party Advisory
- https://lists.apache.org/thread.html/311505e7b7a045aaa246f0a1935703acacf41b95462
FAQ
What is CVE-2017-15694?
CVE-2017-15694 is a vulnerability with a CVSS score of 6.5 (MEDIUM). When an Apache Geode server versions 1.0.0 to 1.8.0 is operating in secure mode, a user with write permissions for specific data regions can modify internal cluster metadata. A malicious user could mo...
How severe is CVE-2017-15694?
CVE-2017-15694 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15694?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Geode.