1.9
CVSSv2

CVE-2014-0018

Published: 14/02/2014 Updated: 07/01/2017
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
VMScore: 171
Vector: AV:L/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to modify the server via a crafted deployment.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform 6.2.0

redhat jboss wildfly application server -

Vendor Advisories

In Red Hat JBoss Enterprise Application Platform, when running under a security manager, it was possible for deployed code to get access to the Modular Service Container (MSC) service registry without any permission checks This could allow malicious deployments to modify the internal state of the server in various ways ...