7.5
CVSSv2

CVE-2003-0845

Published: 17/11/2003 Updated: 24/03/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote malicious users to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jboss jboss 3.0.8

jboss jboss 3.2.1

Exploits

source: wwwsecurityfocuscom/bid/8773/info A remote command-injection vulnerability has been reported in JBoss The issue is reportedly exposed via the HSQLDB component, which is a SQL database server that manages JMS connections Because of a number of flaws, an attacker can pass commands to the HSQLDB component via the port it listens on ...