CVE-2014-0005
published 2015-02-20CVE-2014-0005: PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote…
PriorityP412low3.6CVSS 2.0
AVLACLAuNCPIPAN
EPSS
0.80%
52.4th percentile
PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_brms_platform | <= 6.0.3 | — |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hxxr-j64h-hx75: PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6
ghsa_unreviewed·2022-05-17
CVE-2014-0005 [LOW] GHSA-hxxr-j64h-hx75: PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6
PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.
Red Hat
PicketBox/JBossSX: Unauthorized access to and modification of application server configuration and state by application
vendor_redhat·2014-03-31·CVSS 3.6
CVE-2014-0005 [LOW] CWE-862 PicketBox/JBossSX: Unauthorized access to and modification of application server configuration and state by application
PicketBox/JBossSX: Unauthorized access to and modification of application server configuration and state by application
PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.
It was identified that PicketBox/JBossSX allowed any deployed application to alter or read the underlying application server configuration and state without any authorization checks. An attacker able to deploy applications could use this flaw to circumvent security constraints applied to other applications deployed on the same system, disclose privileged information, and in certain cases allow arbitra
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-0343.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0344.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0345.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0234.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0235.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0343.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0344.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0345.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0234.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0235.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0720.html
2015-02-20
Published