CVE-2025-0736
Estado: AplazadaMedia (5.5)—
A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and exploitation by malicious actors.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-532
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-0736",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-0736",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-01-28T14:38:23.466699Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "15.1.5",
"versionType": "semver"
},
{
"status": "affected",
"version": "0",
"lessThan": "15.0.13",
"versionType": "semver"
},
{
"status": "affected",
"version": "0",
"lessThan": "14.0.34",
"versionType": "semver"
}
],
"packageName": "org.infinispan-infinispan-parent",
"collectionURL": "https://mvnrepository.com/artifact/org.infinispan/infinispan-parent",
"defaultStatus": "unaffected"
},
{
"cpes": [
"cpe:/a:redhat:jboss_data_grid:8"
],
"vendor": "Red Hat",
"product": "Red Hat Data Grid",
"packageName": "org.infinispan-infinispan-parent",
"collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-01-28T09:15:09.543",
"references": [
{
"url": "https://access.redhat.com/errata/RHSA-2025:2663",
"source": "secalert@redhat.com"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2025-0736",
"source": "secalert@redhat.com"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2342233",
"source": "secalert@redhat.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "secalert@redhat.com",
"description": [
{
"lang": "en",
"value": "CWE-532"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw was found in Infinispan, when using JGroups with JDBC_PING. This issue occurs when an application inadvertently exposes sensitive information, such as configuration details or credentials, through logging mechanisms. This exposure can lead to unauthorized access and exploitation by malicious actors."
},
{
"lang": "es",
"value": "Se encontró una falla en Infinispan al usar JGroups con JDBC_PING. Este problema ocurre cuando una aplicación expone inadvertidamente información confidencial, como detalles de configuración o credenciales, a través de mecanismos de registro. Esta exposición puede provocar acceso no autorizado y explotación por parte de actores maliciosos."
}
],
"lastModified": "2026-06-17T08:27:04.217",
"sourceIdentifier": "secalert@redhat.com"
}