Vulnerability Name: | CVE-2014-0005 (CCN-102532) | ||||||||
Assigned: | 2013-02-03 | ||||||||
Published: | 2013-02-03 | ||||||||
Updated: | 2015-03-28 | ||||||||
Summary: | PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application. | ||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N) 2.6 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-0005 Source: REDHAT Type: Vendor Advisory RHSA-2014:0343 Source: REDHAT Type: Vendor Advisory RHSA-2014:0344 Source: REDHAT Type: Vendor Advisory RHSA-2014:0345 Source: REDHAT Type: Vendor Advisory RHSA-2015:0234 Source: REDHAT Type: Vendor Advisory RHSA-2015:0235 Source: REDHAT Type: UNKNOWN RHSA-2015:0720 Source: CCN Type: Red Hat Web site Red Hat JBoss Enterprise Application Platform Source: XF Type: UNKNOWN redhat-jboss-cve20140005-sec-bypass(102532) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |