Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14843

Опубликовано: 17 сент. 2019
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7 are vulnerable to this issue.

A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks.

Меры по смягчению последствий

This flaw only affects the Security Manager running under JDK 11 or 8. To mitigate exposure to this flaw, do not run under those JDK versions.

Дополнительная информация

Статус:

Important
Дефект:
CWE-592
https://bugzilla.redhat.com/show_bug.cgi?id=1752980wildfly-security-manager: security manager authorization bypass

EPSS

Процентиль: 40%
0.00187
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 6 лет назад

A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7 are vulnerable to this issue.

CVSS3: 8.8
debian
около 6 лет назад

A flaw was found in Wildfly Security Manager, running under JDK 11 or ...

github
больше 3 лет назад

A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7 are vulnerable to this issue.

CVSS3: 5
fstec
больше 6 лет назад

Уязвимость менеджера Wildfly Security платформы Red Hat JBoss Operations Network, позволяющая нарушителю получить доступ к защищаемой информации

EPSS

Процентиль: 40%
0.00187
Низкий

7.5 High

CVSS3

Уязвимость CVE-2019-14843