Description
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7 are vulnerable to this issue.
Published: 2020-01-07
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2019-5967 A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7 are vulnerable to this issue.
History

Mon, 26 Aug 2024 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat jboss Enterprise Application Platform Eus
CPEs cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7
Vendors & Products Redhat jboss Enterprise Application Platform Eus

Subscriptions

Redhat Jboss Enterprise Application Platform Jboss Enterprise Application Platform Eus Jboss Single Sign On Red Hat Single Sign On Single Sign-on
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-05T00:26:39.115Z

Reserved: 2019-08-10T00:00:00.000Z

Link: CVE-2019-14843

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-07T17:15:11.143

Modified: 2024-11-21T04:27:28.913

Link: CVE-2019-14843

cve-icon Redhat

Severity : Important

Publid Date: 2019-09-17T00:00:00Z

Links: CVE-2019-14843 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses