QID 730607

Date Published: 2022-09-26

QID 730607: Apache Geode deserialization of untrusted data flaw when using Java Management Extensions (JMX) over Remote Method Invocation (RMI) on Java 11 Vulnerability

Apache Geode is a data management platform that provides real-time, consistent access to data-intensive applications throughout widely distributed cloud architectures.

Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Affected Version
Apache Geode up to 1.12.2 and 1.13.2 .0 QID Detection Logic:
This QID will check for the affected Apache Geode server version

TBA

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Any user wishing to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode 1.15. Use of 1.15 on Java 11 will automatically protect JMX over RMI against deserialization attacks.

    CVEs related to QID 730607

    Software Advisories
    Advisory ID Software Component Link
    GEODE Linux URL Logo lists.apache.org/thread/mg87rh3h773h8sjpm7dhqyldwwtswq7r