Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8175

Опубликовано: 23 июн. 2015
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.

It was found that JBoss Fuse would allow any user defined in the users.properties file to access the HawtIO console without having a valid admin role. This could allow a remote attacker to bypass intended authentication HawtIO console access restrictions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Web Server 1fuse-6.1Affected
Red Hat JBoss A-MQ 6.2FixedRHSA-2015:117723.06.2015
Red Hat JBoss Fuse 6.2FixedRHSA-2015:117623.06.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=1205112Fuse: insufficient access permissions checks when accessing Hawtio console

EPSS

Процентиль: 41%
0.00191
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

nvd
больше 10 лет назад

Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.

github
больше 3 лет назад

Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.

EPSS

Процентиль: 41%
0.00191
Низкий

6.8 Medium

CVSS2