PT-2019-13854 · Red Hat · Wildfly-Core
CVE-2019-14838
·
Publicado
2019-10-14
·
Atualizado
2022-05-24
CVSS v3.1
5.2
Média
| Vetor | AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Wildfly-core versions prior to 7.2.5.GA
Description
A flaw was found that allows Management users with Monitor, Auditor, and Deployer Roles to modify the runtime state of the server, which they should not be allowed to do.
Recommendations
For versions prior to 7.2.5.GA, update to version 7.2.5.GA or later to resolve the issue.
Correção
DoS
Improper Privilege Management
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Wildfly-Core