PT-2019-13854 · Red Hat · Wildfly-Core
Published
2019-10-14
·
Updated
2022-05-24
·
CVE-2019-14838
CVSS v3.1
5.2
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Wildfly-core versions prior to 7.2.5.GA
Description
A flaw was found that allows Management users with Monitor, Auditor, and Deployer Roles to modify the runtime state of the server, which they should not be allowed to do.
Recommendations
For versions prior to 7.2.5.GA, update to version 7.2.5.GA or later to resolve the issue.
Fix
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wildfly-Core