PT-2021-23390 · Red Hat+1 · Jboss+1

Published

2021-10-22

·

Updated

2021-10-28

·

CVE-2021-41744

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions yongyou PLM (affected versions not specified)
Description The issue affects yongyou PLM, which is a Product Life Cycle Management system applying a series of enterprise application systems to support the entire process from conceptual design to the end of product life. It uses jboss by default and allows access to the management control background without authorization. An attacker can exploit this to gain server permissions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41744

Affected Products

Jboss
Yongyou Plm