6.3
CVSSv2

CVE-2020-14299

Published: 16/10/2020 Updated: 27/10/2020
CVSS v2 Base Score: 6.3 | Impact Score: 6.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 561
Vector: AV:N/AC:M/Au:S/C:N/I:N/A:C

Vulnerability Summary

A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an malicious user to perform a complete authentication bypass by using an arbitrary user and password. The highest threat to vulnerability is to system availability.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform

redhat openshift application runtimes -

redhat single sign-on 7.0

Vendor Advisories

Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 733 security update on RHEL 8 Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 73 for RHEL 8Red Hat Product Security has rated this update as having a security imp ...
Synopsis Moderate: Red Hat Single Sign-On 743 security update Type/Severity Security Advisory: Moderate Topic A security update is now available for Red Hat Single Sign-On 74 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnera ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 733 security update on RHEL 7 Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 73 for RHEL 7Red Hat Product Security has rated this update as having a security imp ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 733 security update on RHEL 6 Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 73 for RHEL 6Red Hat Product Security has rated this update as having a security imp ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 733 security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat JBoss Enterprise Application Platform 73Red Hat Product Security has rated this update as having a security impact of Moderate A Co ...
Synopsis Important: Red Hat build of Thorntail 272 security and bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat build of ThorntailRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...