A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HRed Hat Jboss Enterprise Application Platform
APPRedhat6.0.07.0.0Red Hat Wildfly
APPRedhat≤ 16.0.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
References
Related vulnerabilities
CVE-2017-12149CRITICAL9.8⚠ KEVPL ✓same product
RCE przez niebezpieczną deserializację w JBoss HTTP Invoker (EAP 5.2)
CVE-2025-12543CRITICAL9.6PL ✓same product
Brak walidacji nagłówka Host w serwerze Undertow HTTP
CVE-2019-14887CRITICAL9.1PL ✓same product
Wildfly: ignorowanie 'enabled-protocols' umożliwia TLS downgrade
CVE-2019-14892CRITICAL9.8PL ✓same product
RCE poprzez deserializację JNDI w jackson-databind (commons-configuration)
CVE-2019-20444CRITICAL9.1PL ✓same product
Netty: nieprawidłowe parsowanie nagłówków HTTP bez dwukropka (HTTP Request Smuggling)