4.9
CVE-2019-14838
- EPSS 1.14%
- Veröffentlicht 14.10.2019 15:15:09
- Zuletzt bearbeitet 21.11.2024 04:27:28
- Erkennungen
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Wildfly Core Version 7.0.0 Update -
Redhat ≫ Wildfly Core Version 7.0.0 Update alpha1
Redhat ≫ Wildfly Core Version 7.0.0 Update alpha2
Redhat ≫ Wildfly Core Version 7.0.0 Update alpha3
Redhat ≫ Wildfly Core Version 7.0.0 Update alpha4
Redhat ≫ Wildfly Core Version 7.0.0 Update alpha5
Redhat ≫ Wildfly Core Version 7.0.0 Update beta1
Redhat ≫ Wildfly Core Version 7.0.0 Update cr1
Redhat ≫ Jboss Enterprise Application Platform Version 7.2.0
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Jboss Enterprise Application Platform Version 7.2.5
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Jboss Enterprise Application Platform Version 7.3.0
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Single Sign-on Version 7.3.5
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Jboss Enterprise Application Platform Version 7.2.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.14% | 0.625 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:P/A:N
|
| RedHat | 5.2 | 0.9 | 4.2 |
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
https://access.redhat.com/errata/RHSA-2019:4018
https://access.redhat.com/errata/RHSA-2019:4019
https://access.redhat.com/errata/RHSA-2019:4020
https://access.redhat.com/errata/RHSA-2019:4021
https://access.redhat.com/errata/RHSA-2019:4040
https://access.redhat.com/errata/RHSA-2019:4041
https://access.redhat.com/errata/RHSA-2019:4042
https://access.redhat.com/errata/RHSA-2019:4045
https://access.redhat.com/errata/RHSA-2019:3082
https://access.redhat.com/errata/RHSA-2019:3083
https://access.redhat.com/errata/RHSA-2020:0728
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14838