CVE-2014-8175Redhat Jboss Fuse vulnerability

CWE-2644 documents4 sources
Severity
6.0MEDIUMNVD
EPSS
0.2%
top 58.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 8
Latest updateMay 17

Description

Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-75xc-rff6-hh5r: Red Hat JBoss Fuse before 62022-05-17
CVEList
CVE-2014-8175: Red Hat JBoss Fuse before 62015-07-08

💬Community

1
Bugzilla
CVE-2014-8175 JBoss Fuse: insufficient access permissions checks when accessing Hawtio console2015-03-24
CVE-2014-8175 — Redhat Jboss Fuse vulnerability | cvebase