Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote code execution as the system user.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-09-21T16:53:50
Updated: 2024-08-03T10:21:32.473Z
Reserved: 2022-07-29T00:00:00
Link: CVE-2022-37027
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-09-21T17:15:09.443
Modified: 2024-11-21T07:14:18.980
Link: CVE-2022-37027
Redhat
No data.