Lucene search

K
cvelistMitreCVELIST:CVE-2022-36437
HistoryDec 29, 2022 - 12:00 a.m.

CVE-2022-36437

2022-12-2900:00:00
mitre
www.cve.org
1
cve-2022-36437
remote attacker access
data manipulation
unauthenticated access
identity theft
cluster vulnerability
version affected

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

60.2%

The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster with the identity of another already authenticated connection. The affected Hazelcast versions are through 4.0.6, 4.1.9, 4.2.5, 5.0.3, and 5.1.2. The affected Hazelcast Jet versions are through 4.5.3.

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

60.2%