Severity
4.9MEDIUM
EPSS
0.4%
top 40.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateMay 24

Description

A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages6 packages

CVEListV5red_hat/wildfly-corebefore 7.2.5.GA
NVDredhat/data_grid7.3.4

🔴Vulnerability Details

3
OSV
Wildfly Authorization Misconfiguration2022-05-24
GHSA
Wildfly Authorization Misconfiguration2022-05-24
CVEList
CVE-2019-14838: A flaw was found in wildfly-core before 72019-10-14

📋Vendor Advisories

1
Red Hat
wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default2019-10-11

💬Community

1
Bugzilla
CVE-2019-14838 wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default2019-09-11
CVE-2019-14838 (MEDIUM CVSS 4.9) | A flaw was found in wildfly-core be | cvebase.io