CVE-2019-14838
published 2019-10-14CVE-2019-14838: A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime…
PriorityP424medium4.9CVSS 3.1
AVNACLPRHUINSUCNIHAN
EPSS
1.14%
63.1th percentile
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | wildfly-core | — | — |
| redhat | data_grid | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | single_sign-on | — | — |
| redhat | wildfly_core | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
nvdv3.05.2MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Wildfly Authorization Misconfiguration
osv·2022-05-24
CVE-2019-14838 [MEDIUM] Wildfly Authorization Misconfiguration
Wildfly Authorization Misconfiguration
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
GHSA
Wildfly Authorization Misconfiguration
ghsa·2022-05-24
CVE-2019-14838 [MEDIUM] CWE-284 Wildfly Authorization Misconfiguration
Wildfly Authorization Misconfiguration
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
Red Hat
wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default
vendor_redhat·2019-10-11·CVSS 4.9
CVE-2019-14838 [MEDIUM] CWE-284 wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default
wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
It was found that Wildfly users had default user permissions set incorrectly. A malicious user could use this flaw to access unauthorized controls for the application server.
Package: wildfly-core (Red Hat Decision Manager 7) - Not affected
Package: wildfly-core (Red Hat JBoss Data Virtualization 6) - Not affected
Package: jbossas (Red Hat JBoss Enterprise Application Platform 6) - Not affected
Package: wildfly-core (Red Hat JBoss Fuse 6) - Out of support scope
Package: wildfly-core (Red Hat JBoss Operations Network 3) -
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2019:3082https://access.redhat.com/errata/RHSA-2019:3083https://access.redhat.com/errata/RHSA-2019:4018https://access.redhat.com/errata/RHSA-2019:4019https://access.redhat.com/errata/RHSA-2019:4020https://access.redhat.com/errata/RHSA-2019:4021https://access.redhat.com/errata/RHSA-2019:4040https://access.redhat.com/errata/RHSA-2019:4041https://access.redhat.com/errata/RHSA-2019:4042https://access.redhat.com/errata/RHSA-2019:4045https://access.redhat.com/errata/RHSA-2020:0728https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14838https://access.redhat.com/errata/RHSA-2019:3082https://access.redhat.com/errata/RHSA-2019:3083https://access.redhat.com/errata/RHSA-2019:4018https://access.redhat.com/errata/RHSA-2019:4019https://access.redhat.com/errata/RHSA-2019:4020https://access.redhat.com/errata/RHSA-2019:4021https://access.redhat.com/errata/RHSA-2019:4040https://access.redhat.com/errata/RHSA-2019:4041https://access.redhat.com/errata/RHSA-2019:4042https://access.redhat.com/errata/RHSA-2019:4045https://access.redhat.com/errata/RHSA-2020:0728https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14838
2019-10-14
Published