HIGH🇵🇱 Wersja polska

CVE-2019-14843

CVSS 8.8v3.1pub. 2020-01-07upd. 2024-11-21

A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7 are vulnerable to this issue.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Red Hat Jboss Enterprise Application Platform

    APP
    Redhat
    7.2.0
  • Red Hat Single Sign On

    APP
    Redhat
    7.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2017-12149CRITICAL9.8⚠ KEVPL ✓same product

RCE przez niebezpieczną deserializację w JBoss HTTP Invoker (EAP 5.2)

CVE-2025-12543CRITICAL9.6PL ✓same product

Brak walidacji nagłówka Host w serwerze Undertow HTTP

CVE-2022-4361CRITICAL10.0PL ✓same product

XSS w Keycloak — podatność w obsłudze SAML/OIDC umożliwia wykonanie złośliwych skryptów

CVE-2019-14887CRITICAL9.1PL ✓same product

Wildfly: ignorowanie 'enabled-protocols' umożliwia TLS downgrade

CVE-2019-14892CRITICAL9.8PL ✓same product

RCE poprzez deserializację JNDI w jackson-databind (commons-configuration)