PT-2019-13854 · Red Hat · Wildfly-Core
CVE-2019-14838
·
Published
2019-10-14
·
Updated
2022-05-24
CVSS v3.1
5.2
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Wildfly-core versions prior to 7.2.5.GA
Description
A flaw was found that allows Management users with Monitor, Auditor, and Deployer Roles to modify the runtime state of the server, which they should not be allowed to do.
Recommendations
For versions prior to 7.2.5.GA, update to version 7.2.5.GA or later to resolve the issue.
Fix
DoS
Improper Privilege Management
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wildfly-Core