Описание
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
A flaw was discovered in wildfly that would allow local users, who are able to execute init.d script, to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Decision Manager 7 | wildfly | Not affected | ||
| Red Hat JBoss Data Virtualization 6 | jbossas | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 5 | jbossas | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 6 | jbossas | Will not fix | ||
| Red Hat JBoss Fuse 6 | wildfly | Out of support scope | ||
| Red Hat JBoss Fuse Service Works 6 | jbossas | Out of support scope | ||
| Red Hat JBoss Operations Network 3 | wildfly | Not affected | ||
| Red Hat JBoss SOA Platform 5 | jbossas | Not affected | ||
| Red Hat OpenShift Application Runtimes | wildfly | Not affected | ||
| Red Hat Process Automation 7 | wildfly | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
A flaw was discovered in wildfly versions up to 16.0.0.Final that woul ...
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Уязвимость Java-сервера приложений WildFly, вызванная ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю завершать произвольные процессы в системе
EPSS
5.5 Medium
CVSS3