CVE-2017-9796 is a vulnerability in Apache Geode
Published on January 10, 2018
When an Apache Geode cluster before v1.3.0 is operating in secure mode, a user with read access to specific regions within a Geode cluster may execute OQL queries containing a region name as a bind parameter that allow read access to objects within unauthorized regions.
Products Associated with CVE-2017-9796
Want to know whenever a new CVE is published for Apache Geode? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Geode Version 1.0.0 to 1.2.1 is affected by CVE-2017-9796Exploit Probability
EPSS
0.11%
Percentile
30.06%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.