| Vulnerability Name: | CVE-2015-0297 (CCN-102539) | ||||||||
| Assigned: | 2014-11-18 | ||||||||
| Published: | 2015-04-21 | ||||||||
| Updated: | 2015-10-05 | ||||||||
| Summary: | Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager. | ||||||||
| CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:C) 6.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:C/E:U/RL:OF/RC:C)
5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
| Vulnerability Type: | CWE-284 | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2015-0297 Source: REDHAT Type: Vendor Advisory RHSA-2015:0862 Source: SECTRACK Type: UNKNOWN 1032181 Source: CCN Type: Red Hat Bugzilla Bug 1198008 (CVE-2015-0297) CVE-2015-0297 RHQ: ServerInvokerServlet remote code exec Source: XF Type: UNKNOWN jboss-operations-cve20150297-code-exec(102539) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||