A vulnerability in the application environment of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to gain unauthorized access to the JBoss Enterprise Application Platform (JBoss EAP) on an affected device. The vulnerability is due to an incorrect configuration of the authentication settings on the JBoss EAP. An attacker could exploit this vulnerability by authenticating with a specific low-privilege account. A successful exploit could allow the attacker to gain unauthorized access to the JBoss EAP, which should be limited to internal system accounts.
History

Fri, 15 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2020-01-06T07:45:16.625398Z

Updated: 2024-11-15T17:52:40.426Z

Reserved: 2019-09-06T00:00:00

Link: CVE-2019-15999

cve-icon Vulnrichment

Updated: 2024-08-05T01:03:32.630Z

cve-icon NVD

Status : Modified

Published: 2020-01-06T08:15:11.580

Modified: 2024-11-21T04:29:54.227

Link: CVE-2019-15999

cve-icon Redhat

No data.