CVE-2019-14841
published 2022-10-17CVE-2019-14841: A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin…
PriorityP351high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.62%
45.5th percentile
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | decision_manager | — | — |
| redhat | process_automation | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hcqh-2x7m-p53x: A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header
ghsa_unreviewed·2022-10-17
CVE-2019-14841 [HIGH] CWE-281 GHSA-hcqh-2x7m-p53x: A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.
Red Hat
RHDM: admin console auth bypass
vendor_redhat·2021-07-15·CVSS 8.8
CVE-2019-14841 [HIGH] CWE-281 RHDM: admin console auth bypass
RHDM: admin console auth bypass
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.
Package: Business-central (Red Hat Decision Manager 7) - Will not fix
Package: Business-central (Red Hat Process Automation 7) - Will not fix
No detection rules found.
No public exploits indexed.
2022-10-17
Published