CVE-2014-0018 — Incorrect Type Conversion or Cast in Redhat Jboss Enterprise Application Platform
CWE-264CWE-704 — Incorrect Type Conversion or CastCWE-430 — Deployment of Wrong HandlerCWE-754 — Improper Check for Unusual or Exceptional ConditionsCWE-362 — Race ConditionCWE-269 — Improper Privilege ManagementCWE-99 — Resource InjectionCWE-460 — Improper Cleanup on Thrown ExceptionCWE-476 — NULL Pointer DereferenceCWE-416 — Use After FreeCWE-20 — Improper Input ValidationCWE-835 — Infinite LoopCWE-628 — Function Call with Incorrectly Specified Arguments26 documents6 sources
Severity
1.9LOWNVD
EPSS
0.1%
top 80.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 14
Latest updateNov 12
Description
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to modify the server via a crafted deployment.
CVSS vector
AV:L/AC:M/C:N/I:P/A:NExploitability: 3.4 | Impact: 2.9
Affected Packages1 packages
🔴Vulnerability Details
2📋Vendor Advisories
6Red Hat
▶
💬Community
1Bugzilla
▶