hazelcast records
9 published records for vendor hazelcast.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 77.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication1
- CWE-384 Session Fixation1
- CWE-502 Deserialization of Untrusted Data1
- CWE-522 Insufficiently Protected Credentials1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-0265Proof of concept | Improper Restriction of XML External Entity Reference in hazelcast/hazelcasthazelcast · hazelcast · CWE-611 | Critical9.8 | — | 2.8% | Mar 3, 2022 |
39Monitor | CVE-2020-26168No exploit | The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn'thazelcast · hazelcast · CWE-287 | Critical9.8 | — | 1.6% | Nov 9, 2020 |
39Monitor | CVE-2024-56518No exploit | Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML documhazelcast · management center · CWE-94 | Critical9.8 | — | 1.0% | Apr 17, 2025 |
36Monitor | CVE-2022-36437No exploit | The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster hazelcast · hazelcast · CWE-384 | Critical9.1 | — | 1.0% | Dec 29, 2022 |
35Monitor | CVE-2023-33265No exploit | In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing auhazelcast · hazelcast · CWE-862 | High8.8 | — | 0.7% | Jul 18, 2023 |
33Monitor | CVE-2016-10750No exploit | In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization.hazelcast · hazelcast · CWE-502 | High8.1 | — | 4.0% | May 22, 2019 |
30Monitor | CVE-2023-45859No exploit | In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client hazelcast · hazelcast · CWE-922 | High7.6 | — | 0.5% | Feb 28, 2024 |
26Monitor | CVE-2023-45860No exploit | In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector.hazelcast · hazelcast · CWE-89 | Medium6.5 | — | 0.5% | Feb 16, 2024 |
17Monitor | CVE-2023-33264No exploit | In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuratiohazelcast · hazelcast · CWE-522 | Medium4.3 | — | 0.7% | May 21, 2023 |
- CVE-2022-026540Plan
Improper Restriction of XML External Entity Reference in hazelcast/hazelcast
CriticalCVSS 9.8Proof of conceptEPSS 3%hazelcast · hazelcastMar 3, 2022
- CVE-2020-2616839Monitor
The LDAP authentication method in LdapLoginModule in Hazelcast IMDG Enterprise 4.x before 4.0.3, and Jet Enterprise 4.x through 4.2, doesn't
CriticalCVSS 9.8No exploitEPSS 2%hazelcast · hazelcastNov 9, 2020
- CVE-2024-5651839Monitor
Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML docum
CriticalCVSS 9.8No exploitEPSS 1%hazelcast · management centerApr 17, 2025
- CVE-2022-3643736Monitor
The Connection handler in Hazelcast and Hazelcast Jet allows a remote unauthenticated attacker to access and manipulate data in the cluster
CriticalCVSS 9.1No exploitEPSS 1%hazelcast · hazelcastDec 29, 2022
- CVE-2023-3326535Monitor
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, executor services don't check client permissions properly, allowing au
HighCVSS 8.8No exploitEPSS 1%hazelcast · hazelcastJul 18, 2023
- CVE-2016-1075033Monitor
In Hazelcast before 3.11, the cluster join procedure is vulnerable to remote code execution via Java deserialization.
HighCVSS 8.1No exploitEPSS 4%hazelcast · hazelcastMay 22, 2019
- CVE-2023-4585930Monitor
In Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client
HighCVSS 7.6No exploitEPSS 1%hazelcast · hazelcastFeb 28, 2024
- CVE-2023-4586026Monitor
In Hazelcast Platform through 5.3.4, a security issue exists within the SQL mapping for the CSV File Source connector.
MediumCVSS 6.5No exploitEPSS 1%hazelcast · hazelcastFeb 16, 2024
- CVE-2023-3326417Monitor
In Hazelcast through 5.0.4, 5.1 through 5.1.6, and 5.2 through 5.2.3, configuration routines don't mask passwords in the member configuratio
MediumCVSS 4.3No exploitEPSS 1%hazelcast · hazelcastMay 21, 2023