Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14838

Опубликовано: 11 окт. 2019
Источник: redhat
CVSS3: 5.2
EPSS Низкий

Описание

A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server

It was found that Wildfly users had default user permissions set incorrectly. A malicious user could use this flaw to access unauthorized controls for the application server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7wildfly-coreNot affected
Red Hat JBoss Data Virtualization 6wildfly-coreNot affected
Red Hat JBoss Enterprise Application Platform 6jbossasNot affected
Red Hat JBoss Fuse 6wildfly-coreOut of support scope
Red Hat JBoss Operations Network 3wildfly-coreOut of support scope
Red Hat OpenShift Application Runtimeswildfly-coreAffected
Red Hat Process Automation 7wildfly-coreNot affected
Red Hat Data Grid 7.3.4wildfly-coreFixedRHSA-2020:072805.03.2020
Red Hat JBoss EAP 7.2wildfly-coreFixedRHSA-2019:308315.10.2019
Red Hat JBoss EAP 7.2wildfly-coreFixedRHSA-2019:402126.11.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-284
https://bugzilla.redhat.com/show_bug.cgi?id=1751227wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default

EPSS

Процентиль: 59%
0.00381
Низкий

5.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
nvd
больше 6 лет назад

A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server

CVSS3: 4.9
debian
больше 6 лет назад

A flaw was found in wildfly-core before 7.2.5.GA. The Management users ...

CVSS3: 4.9
github
больше 3 лет назад

Wildfly Authorization Misconfiguration

EPSS

Процентиль: 59%
0.00381
Низкий

5.2 Medium

CVSS3