CVE-2015-5304Missing Authorization in Redhat Jboss Enterprise Application Platform

Severity
3.5LOWNVD
EPSS
1.3%
top 20.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 16
Latest updateMay 17

Description

Red Hat JBoss Enterprise Application Platform (EAP) before 6.4.5 does not properly authorize access to shut down the server, which allows remote authenticated users with the Monitor, Deployer, or Auditor role to cause a denial of service via unspecified vectors.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 6.8 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-gvc6-x7v9-m2cq: Red Hat JBoss Enterprise Application Platform (EAP) before 62022-05-17
CVEList
CVE-2015-5304: Red Hat JBoss Enterprise Application Platform (EAP) before 62015-12-16

📋Vendor Advisories

1
Red Hat
EAP: missing authorization check for Monitor/Deployer/Auditor role when shutting down server2015-12-02

💬Community

1
Bugzilla
CVE-2015-5304 JBoss EAP: missing authorization check for Monitor/Deployer/Auditor role when shutting down server2015-10-19
CVE-2015-5304 — Missing Authorization in Redhat | cvebase