Описание
JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression Language (MVEL) expression. NOTE: some of these details are obtained from third party information.
Отчет
This issue does not affect RTgov as shipped with Red Hat JBoss Fuse Service Works 6. It may affect earlier versions of the upstream JBoss Overlord RTGov project. In Red Hat JBoss Fuse Service Works 6, this flaw is mitigated by configuration options that either remove the vulnerable interface, or constrain it using a Java Security Manager policy. These options are documented in the Installation and Security Guides for the product.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Fuse Service Works 6 | RT Governance | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
6 Medium
CVSS2
Связанные уязвимости
JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression Language (MVEL) expression. NOTE: some of these details are obtained from third party information.
JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression Language (MVEL) expression. NOTE: some of these details are obtained from third party information.
EPSS
6 Medium
CVSS2