peter bassill · operator
$ cve CVE-2017-15692 JSON

CVE-2017-15692

9.8
CRITICAL · CVSS 3.0 · EPSS 4.8% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

In Apache Geode before v1.4.0, the TcpServer within the Geode locator opens a network port that deserializes data. If an unprivileged user gains access to the Geode locator, they may be able to cause remote code execution if certain classes are present on the classpath.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.78% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2018-02-27
Last modified2026-06-17

Affected (1)

VendorProduct
apachegeode

References

→ the Explorer  ·  watch your stack  ·  NVD