CVE-2019-14838 MEDIUM

CVE-2019-14838

Vendor Red Hat
Product wildfly-core
Weakness CWE-284
Published October 14, 2019
Last update August 5, 2024

CVSS base score

5.2/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:H

What the vulnerability does

01Description

A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server

Key dates

02Disclosure timeline

October 14, 2019 CVE published
August 5, 2024 Record updated