CVE-2013-6469

CWE-94Code Injection5 documents5 sources
Severity
6.5MEDIUM
EPSS
0.5%
top 34.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateMay 17

Description

JBoss Overlord Run Time Governance (RTGov) 1.0 for JBossAS allows remote authenticated users to execute arbitrary Java code via an MVFLEX Expression Language (MVEL) expression. NOTE: some of these details are obtained from third party information.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

🔴Vulnerability Details

2
GHSA
GHSA-55g4-fvcx-ch9h: JBoss Overlord Run Time Governance (RTGov) 12022-05-17
CVEList
CVE-2013-6469: JBoss Overlord Run Time Governance (RTGov) 12014-04-21

📋Vendor Advisories

1
Red Hat
RTgov: Remote Java Code Execution in MVEL2014-04-09

💬Community

1
Bugzilla
CVE-2013-6469 RTgov: Remote Java Code Execution in MVEL2014-01-10