Severity
9.0CRITICAL
EPSS
0.6%
top 31.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24
Latest updateMay 17

Description

Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.

CVSS vector

AV:N/AC:L/C:P/I:P/A:CExploitability: 10.0 | Impact: 8.5

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-hfm5-vrw2-7m5q: Red Hat JBoss Operations Network 32022-05-17
CVEList
CVE-2015-0297: Red Hat JBoss Operations Network 32015-04-24

📋Vendor Advisories

1
Red Hat
RHQ: ServerInvokerServlet remote code exec2015-04-14

💬Community

1
Bugzilla
CVE-2015-0297 RHQ: ServerInvokerServlet remote code exec2015-03-03