CVE-2014-0005

Severity
3.6LOW
EPSS
0.2%
top 56.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 20
Latest updateMay 17

Description

PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.

CVSS vector

AV:L/AC:L/C:P/I:P/A:NExploitability: 3.9 | Impact: 4.9

🔴Vulnerability Details

2
GHSA
GHSA-hxxr-j64h-hx75: PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 62022-05-17
CVEList
CVE-2014-0005: PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 62015-02-20

📋Vendor Advisories

1
Red Hat
PicketBox/JBossSX: Unauthorized access to and modification of application server configuration and state by application2014-03-31

💬Community

1
Bugzilla
CVE-2014-0005 PicketBox/JBossSX: Unauthorized access to and modification of application server configuration and state by application2014-01-08
CVE-2014-0005 (LOW CVSS 3.6) | PicketBox and JBossSX | cvebase.io