Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0018

Опубликовано: 11 янв. 2014
Источник: redhat
CVSS2: 1.9
EPSS Низкий

Описание

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to modify the server via a crafted deployment.

In Red Hat JBoss Enterprise Application Platform, when running under a security manager, it was possible for deployed code to get access to the Modular Service Container (MSC) service registry without any permission checks. This could allow malicious deployments to modify the internal state of the server in various ways.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 6jboss-as-serverNot affected
Red Hat JBoss Data Virtualization 6jboss-as-serverNot affected
Red Hat JBoss Enterprise Application Platform 5jboss-as-serverNot affected
Red Hat JBoss Enterprise Web Server 1othersNot affected
Red Hat JBoss Operations Network 3jboss-as-serverNot affected
Red Hat JBoss BPMS 6.0jboss-as-serverFixedRHSA-2014:129123.09.2014
Red Hat JBoss BRMS 6.0jboss-as-serverFixedRHSA-2014:129023.09.2014
Red Hat JBoss Enterprise Application Platform 6.2FixedRHSA-2014:017213.02.2014
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 5jbossas-javadocsFixedRHSA-2014:017013.02.2014
Red Hat JBoss Enterprise Application Platform 6.2 for RHEL 6jbossas-javadocsFixedRHSA-2014:017113.02.2014

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1052783jboss-as-server: Unchecked access to MSC Service Registry under JSM

EPSS

Процентиль: 20%
0.00062
Низкий

1.9 Low

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to modify the server via a crafted deployment.

github
больше 3 лет назад

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to modify the server via a crafted deployment.

EPSS

Процентиль: 20%
0.00062
Низкий

1.9 Low

CVSS2