CVE-2015-0297
published 2015-04-24CVE-2015-0297: Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via…
PriorityP348critical9CVSS 2.0
AVNACLAuNCPIPAC
EPSS
2.20%
80.5th percentile
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_operations_network | — | — |
CVSS provenance
nvdv2.09.0CRITICALAV:N/AC:L/Au:N/C:P/I:P/A:C
vendor_redhat9.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
RHQ: ServerInvokerServlet remote code exec
vendor_redhat·2015-04-14·CVSS 9.0
CVE-2015-0297 [CRITICAL] CWE-306 RHQ: ServerInvokerServlet remote code exec
RHQ: ServerInvokerServlet remote code exec
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.
It was discovered that the JBoss Operations Network server did not correctly restrict access to certain remote APIs. A remote, unauthenticated attacker could use this flaw to execute arbitrary Java methods via ServerInvokerServlet or SchedulerService, and possibly exhaust all available disk space via ContentManager.
GHSA
GHSA-hfm5-vrw2-7m5q: Red Hat JBoss Operations Network 3
ghsa_unreviewed·2022-05-17
CVE-2015-0297 [HIGH] CWE-284 GHSA-hfm5-vrw2-7m5q: Red Hat JBoss Operations Network 3
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.
No detection rules found.
No public exploits indexed.
2015-04-24
Published