PT-2014-3434 · Red Hat · Jboss Wildfly Application Server+1

Published

2014-02-14

·

Updated

2017-01-07

·

CVE-2014-0018

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Enterprise Application Platform (JBEAP) version 6.2.0 JBoss WildFly Application Server (affected versions not specified)
Description The issue arises when the software is run under a security manager, as it fails to properly restrict access to the Modular Service Container (MSC) service registry. This allows local users to modify the server by creating a crafted deployment.
Recommendations For Red Hat JBoss Enterprise Application Platform (JBEAP) version 6.2.0, consider restricting access to the Modular Service Container (MSC) service registry until a proper fix is available. For JBoss WildFly Application Server, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-0018
RHSA-2014:0170
RHSA-2014:0171

Affected Products

Jboss Wildfly Application Server
Red Hat Jboss Enterprise Application Platform