Impact
A flaw in WildFly core permits a remote attacker authenticated as a user with the "deployer" role to upload and deploy a malicious archive file through an HTTP POST request. The vulnerability arises from how WildFly processes the archive, allowing the attacker to place arbitrary files on the server. Successful exploitation can enable reading of system files and other sensitive data, thereby compromising confidentiality and potentially the integrity of the application configuration.
Affected Systems
Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Process Automation 7, and Red Hat Single Sign‑On 7 are affected. Version details are not specified, but any current release of these products is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess deployer credentials and to target WildFly over a network where the management interfaces are reachable. Once the malicious archive is deployed, the attacker can read arbitrary files and may leverage the access for further attacks. The mitigation strategy involves limiting the scope and permissions of the deployer role, restricting management interface exposure, and applying vendor patches when they become available.
OpenCVE Enrichment