{"id":"CVE-2017-7536","details":"In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access those private members without the permission an attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue().","aliases":["GHSA-xxgp-pcfc-3vgc"],"modified":"2026-07-08T05:50:33.472036802Z","published":"2018-01-10T15:29:00.283Z","database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"redhat:jboss_enterprise_application_platform","cpes":["cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.4.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"6.0.0"},{"last_affected":"6.0.0"},{"introduced":"6.4.0"},{"last_affected":"6.4.0"},{"introduced":"7.0"},{"last_affected":"7.0"},{"introduced":"7.1"},{"last_affected":"7.1"}]},{"vendor_product":"redhat:satellite","cpes":["cpe:2.3:a:redhat:satellite:6.4:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"6.4"},{"last_affected":"6.4"}],"source":"CPE_STRING"},{"extracted_events":[{"introduced":"6.4"},{"last_affected":"6.4"}],"source":"CPE_STRING","vendor_product":"redhat:satellite_capsule","cpes":["cpe:2.3:a:redhat:satellite_capsule:6.4:*:*:*:*:*:*:*"]},{"cpes":["cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.0"},{"last_affected":"4.0"}],"source":"CPE_STRING","vendor_product":"redhat:virtualization"},{"extracted_events":[{"introduced":"4.0"},{"last_affected":"4.0"}],"source":"CPE_STRING","vendor_product":"redhat:virtualization_host","cpes":["cpe:2.3:a:redhat:virtualization_host:4.0:*:*:*:*:*:*:*"]}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3E"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/101048"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1039744"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2808"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2809"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2810"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:2811"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:3141"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:3454"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:3455"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:3456"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:3458"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2740"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2741"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2742"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2743"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2927"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:3817"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1465573"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hibernate/hibernate-validator","events":[{"introduced":"a93f900f0f91bdfccf98a1825d7cfbd85b8a6c85"},{"fixed":"9a8ee4954d9d6596f0bd87fd66d51deac81724d1"},{"introduced":"a3fa9cee819a8e85ab99e8106c434e175b9d5a3b"},{"fixed":"be5f102e7c9eba64e58b93763befde4284ce9e67"},{"introduced":"b9b5ee347e9231271029561ac8cddab00519e484"},{"fixed":"134a5bddddc15559cc8557ef6c91e8d6d7ff3d08"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:redhat:hibernate_validator:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.2.0"},{"fixed":"5.2.5"},{"introduced":"5.3.0"},{"fixed":"5.3.6"},{"introduced":"5.4.0"},{"fixed":"5.4.2"}]}}],"versions":["5.4.1.Final","5.3.5.Final","5.4.0.Final","5.3.4.Final","5.3.3.Final","5.3.2.Final","5.3.1.Final","5.3.0.Final","5.2.4.Final","5.2.3.Final","5.2.2.Final","5.2.1.Final","5.2.0.Final"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7536.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}