MEDIUM🇵🇱 Wersja polska

CVE-2020-14317

CVSS 5.5v3.1pub. 2021-06-02upd. 2024-11-21

It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
  • Red Hat Jboss Enterprise Application Platform

    APP
    Redhat
    all versions
  • Red Hat Wildfly

    APP
    Redhat
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2017-12149CRITICAL9.8⚠ KEVPL ✓same product

RCE przez niebezpieczną deserializację w JBoss HTTP Invoker (EAP 5.2)

CVE-2025-12543CRITICAL9.6PL ✓same product

Brak walidacji nagłówka Host w serwerze Undertow HTTP

CVE-2019-14887CRITICAL9.1PL ✓same product

Wildfly: ignorowanie 'enabled-protocols' umożliwia TLS downgrade

CVE-2019-14892CRITICAL9.8PL ✓same product

RCE poprzez deserializację JNDI w jackson-databind (commons-configuration)

CVE-2019-20444CRITICAL9.1PL ✓same product

Netty: nieprawidłowe parsowanie nagłówków HTTP bez dwukropka (HTTP Request Smuggling)