6.8
CVSSv2

CVE-2014-0248

Published: 07/07/2014 Updated: 13/02/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote malicious users to execute arbitrary code via a crafted authentication header, related to Seam logging.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise web platform 5.2.0

redhat jboss enterprise application platform 5.2.0

redhat jboss web framework kit 2.5.0

Vendor Advisories

It was found that the orgjbossseamwebAuthenticationFilter class implementation did not properly use Seam logging A remote attacker could send specially crafted authentication headers to an application, which could result in arbitrary code execution with the privileges of the user running that application ...