CVE-2013-6469
published 2014-04-22CVE-2013-6469: JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression Language…
PriorityP432medium6.5CVSS 2.0
AVNACLAuSCPIPAP
EPSS
1.65%
73.9th percentile
JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression Language (MVEL) expression. NOTE: some of these details are obtained from third party information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_fuse_service_works | — | — |
| redhat | jboss_overlord_run_time_governance | — | — |
CVSS provenance
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
RTgov: Remote Java Code Execution in MVEL
vendor_redhat·2014-04-09·CVSS 6.5
CVE-2013-6469 [MEDIUM] RTgov: Remote Java Code Execution in MVEL
RTgov: Remote Java Code Execution in MVEL
JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression Language (MVEL) expression. NOTE: some of these details are obtained from third party information.
Statement: This issue does not affect RTgov as shipped with Red Hat JBoss Fuse Service Works 6. It may affect earlier versions of the upstream JBoss Overlord RTGov project.
In Red Hat JBoss Fuse Service Works 6, this flaw is mitigated by configuration options that either remove the vulnerable interface, or constrain it using a Java Security Manager policy. These options are documented in the Installation and Security Guides for the product.
Package: RT Governance (Red Hat JBoss Fuse Service Works 6) -
GHSA
GHSA-55g4-fvcx-ch9h: JBoss Overlord Run Time Governance (RTGov) 1
ghsa_unreviewed·2022-05-17
CVE-2013-6469 [MEDIUM] CWE-94 GHSA-55g4-fvcx-ch9h: JBoss Overlord Run Time Governance (RTGov) 1
JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression Language (MVEL) expression. NOTE: some of these details are obtained from third party information.
No detection rules found.
No public exploits indexed.
2014-04-22
Published