6
CVSSv2

CVE-2014-8175

Published: 08/07/2015 Updated: 09/07/2015
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Red Hat JBoss Fuse prior to 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss fuse

Vendor Advisories

It was found that JBoss Fuse would allow any user defined in the usersproperties file to access the HawtIO console without having a valid admin role This could allow a remote attacker to bypass intended authentication HawtIO console access restrictions ...