CVE-2025-0736

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 28, 2025
CWE ID 532

Summary

CVE-2025-0736 is a vulnerability affecting Infinispan, a popular open-source data grid platform. The issue arises when JGroups, a component of Infinispan, is utilized with JDBC_PING. This problem stems from the inadvertent exposure of sensitive information through logging mechanisms. Such exposure can encompass configuration details and credentials, providing malicious actors with unauthorized access opportunities. By exploiting this vulnerability, attackers can gain crucial insights into the system, potentially leading to devastating consequences.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share