{"id":"CVE-2014-3558","aliases":["GHSA-845h-985r-jrqh"],"url":"https://o3.security/vulnerability/CVE-2014-3558","summary":"Improper Authentication in Hibernate Validator","details":"ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.","published":"2014-09-30T14:55:08Z","modified":"2026-04-10T03:44:39.579882Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.hibernate:hibernate-validator","fixedVersion":"4.2.1"},{"ecosystem":"Maven","name":"org.hibernate:hibernate-validator","fixedVersion":"4.3.2"},{"ecosystem":"Maven","name":"org.hibernate:hibernate-validator","fixedVersion":"5.1.2"}],"fix":{"url":"https://github.com/hibernate/hibernate-validator/commit/2c95d4ea0ef20977be249e31a4a4f4f4f71c945d","label":"hibernate/hibernate-validator@2c95d4e"},"references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2014-1285.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2014-1286.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2014-1287.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2014-1288.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2015-0125.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2015-0720.html"},{"type":"ADVISORY","url":"https://github.com/victims/victims-cve-db/blob/master/database/java/2014/3558.yaml"},{"type":"ADVISORY","url":"https://hibernate.atlassian.net/browse/HV-912"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3558"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/2c95d4ea0ef20977be249e31a4a4f4f4f71c945d"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/67fdff14831c035c25e098fe14bd86523d17f726"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/7e7131939a4361a7cad3e77ab89a8462132c561c"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/c489416f699a46859c134796b3ccfea41ef3ce52"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/c9525ca544b1281e2b7c7347e86e87c86dc1dc6e"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/e8c42b689df8c6752d635d02c6518da3fece3870"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/f97c2021a03c825abdeca1692f5be51e77e76a8f"},{"type":"WEB","url":"https://github.com/hibernate/hibernate-validator/commit/fd4eaed7fb930db6a5e4c03742b4b3adcfecc90e"},{"type":"PACKAGE","url":"https://github.com/hibernate/hibernate-validator"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:44:39.579882Z"}}