Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-0248

Опубликовано: 23 июн. 2014
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.

It was found that the org.jboss.seam.web.AuthenticationFilter class implementation did not properly use Seam logging. A remote attacker could send specially crafted authentication headers to an application, which could result in arbitrary code execution with the privileges of the user running that application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6seamNot affected
Red Hat JBoss BRMS 5seamWill not fix
Red Hat JBoss BRMS 6seamNot affected
Red Hat JBoss Data Virtualization 6seamNot affected
Red Hat JBoss Enterprise Application Platform 6seamNot affected
Red Hat JBoss Fuse Service Works 6seamNot affected
Red Hat JBoss Operations Network 3seamNot affected
Red Hat JBoss Portal 5seamAffected
Red Hat JBoss Portal 6seamNot affected
Red Hat JBoss SOA Platform 4seamWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=1101619Seam: RCE via unsafe logging in AuthenticationFilter

EPSS

Процентиль: 85%
0.02348
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.

github
больше 3 лет назад

org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.

EPSS

Процентиль: 85%
0.02348
Низкий

6.8 Medium

CVSS2