PT-2014-3434 · Red Hat · Jboss Wildfly Application Server+1

Publicado

2014-02-14

·

Atualizado

2017-01-07

·

CVE-2014-0018

CVSS v2.0

1.9

Baixa

VetorAV:L/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Enterprise Application Platform (JBEAP) version 6.2.0 JBoss WildFly Application Server (affected versions not specified)
Description The issue arises when the software is run under a security manager, as it fails to properly restrict access to the Modular Service Container (MSC) service registry. This allows local users to modify the server by creating a crafted deployment.
Recommendations For Red Hat JBoss Enterprise Application Platform (JBEAP) version 6.2.0, consider restricting access to the Modular Service Container (MSC) service registry until a proper fix is available. For JBoss WildFly Application Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0018
RHSA-2014:0170
RHSA-2014:0171

Produtos afetados

Jboss Wildfly Application Server
Red Hat Jboss Enterprise Application Platform