// For flags

CVE-2019-14838

wildfly-core: Incorrect privileges for 'Monitor', 'Auditor' and 'Deployer' user by default

Severity Score

4.9
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server

Se detectó un error en wildfly-core en versiones anteriores a la 7.2.5.GA. Los usuarios de administración con funciones de monitor, auditor e implementador no deberían poder modificar el estado de tiempo de ejecución del servidor

It was found that Wildfly users had default user permissions set incorrectly. A malicious user could use this flaw to access unauthorized controls for the application server.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-08-10 CVE Reserved
  • 2019-10-14 CVE Published
  • 2024-02-07 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-269: Improper Privilege Management
  • CWE-284: Improper Access Control
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform
Search vendor "Redhat" for product "Jboss Enterprise Application Platform"
7.2.0
Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.2.0"
-
Affected
in Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
6.0
Search vendor "Redhat" for product "Enterprise Linux" and version "6.0"
-
Safe
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform
Search vendor "Redhat" for product "Jboss Enterprise Application Platform"
7.2.0
Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.2.0"
-
Affected
in Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
7.0
Search vendor "Redhat" for product "Enterprise Linux" and version "7.0"
-
Safe
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform
Search vendor "Redhat" for product "Jboss Enterprise Application Platform"
7.2.0
Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.2.0"
-
Affected
in Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
8.0
Search vendor "Redhat" for product "Enterprise Linux" and version "8.0"
-
Safe
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform
Search vendor "Redhat" for product "Jboss Enterprise Application Platform"
7.2.5
Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.2.5"
-
Affected
in Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
6.0
Search vendor "Redhat" for product "Enterprise Linux" and version "6.0"
-
Safe
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform
Search vendor "Redhat" for product "Jboss Enterprise Application Platform"
7.2.5
Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.2.5"
-
Affected
in Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
7.0
Search vendor "Redhat" for product "Enterprise Linux" and version "7.0"
-
Safe
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform
Search vendor "Redhat" for product "Jboss Enterprise Application Platform"
7.2.5
Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.2.5"
-
Affected
in Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
8.0
Search vendor "Redhat" for product "Enterprise Linux" and version "8.0"
-
Safe
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform
Search vendor "Redhat" for product "Jboss Enterprise Application Platform"
7.3.0
Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.3.0"
-
Affected
in Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
6.0
Search vendor "Redhat" for product "Enterprise Linux" and version "6.0"
-
Safe
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform
Search vendor "Redhat" for product "Jboss Enterprise Application Platform"
7.3.0
Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.3.0"
-
Affected
in Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
7.0
Search vendor "Redhat" for product "Enterprise Linux" and version "7.0"
-
Safe
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform
Search vendor "Redhat" for product "Jboss Enterprise Application Platform"
7.3.0
Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.3.0"
-
Affected
in Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
8.0
Search vendor "Redhat" for product "Enterprise Linux" and version "8.0"
-
Safe
Redhat
Search vendor "Redhat"
Single Sign-on
Search vendor "Redhat" for product "Single Sign-on"
7.3.5
Search vendor "Redhat" for product "Single Sign-on" and version "7.3.5"
-
Affected
in Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
6.0
Search vendor "Redhat" for product "Enterprise Linux" and version "6.0"
-
Safe
Redhat
Search vendor "Redhat"
Single Sign-on
Search vendor "Redhat" for product "Single Sign-on"
7.3.5
Search vendor "Redhat" for product "Single Sign-on" and version "7.3.5"
-
Affected
in Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
7.0
Search vendor "Redhat" for product "Enterprise Linux" and version "7.0"
-
Safe
Redhat
Search vendor "Redhat"
Single Sign-on
Search vendor "Redhat" for product "Single Sign-on"
7.3.5
Search vendor "Redhat" for product "Single Sign-on" and version "7.3.5"
-
Affected
in Redhat
Search vendor "Redhat"
Enterprise Linux
Search vendor "Redhat" for product "Enterprise Linux"
8.0
Search vendor "Redhat" for product "Enterprise Linux" and version "8.0"
-
Safe
Redhat
Search vendor "Redhat"
Wildfly Core
Search vendor "Redhat" for product "Wildfly Core"
7.0.0
Search vendor "Redhat" for product "Wildfly Core" and version "7.0.0"
-
Affected
Redhat
Search vendor "Redhat"
Wildfly Core
Search vendor "Redhat" for product "Wildfly Core"
7.0.0
Search vendor "Redhat" for product "Wildfly Core" and version "7.0.0"
alpha1
Affected
Redhat
Search vendor "Redhat"
Wildfly Core
Search vendor "Redhat" for product "Wildfly Core"
7.0.0
Search vendor "Redhat" for product "Wildfly Core" and version "7.0.0"
alpha2
Affected
Redhat
Search vendor "Redhat"
Wildfly Core
Search vendor "Redhat" for product "Wildfly Core"
7.0.0
Search vendor "Redhat" for product "Wildfly Core" and version "7.0.0"
alpha3
Affected
Redhat
Search vendor "Redhat"
Wildfly Core
Search vendor "Redhat" for product "Wildfly Core"
7.0.0
Search vendor "Redhat" for product "Wildfly Core" and version "7.0.0"
alpha4
Affected
Redhat
Search vendor "Redhat"
Wildfly Core
Search vendor "Redhat" for product "Wildfly Core"
7.0.0
Search vendor "Redhat" for product "Wildfly Core" and version "7.0.0"
alpha5
Affected
Redhat
Search vendor "Redhat"
Wildfly Core
Search vendor "Redhat" for product "Wildfly Core"
7.0.0
Search vendor "Redhat" for product "Wildfly Core" and version "7.0.0"
beta1
Affected
Redhat
Search vendor "Redhat"
Wildfly Core
Search vendor "Redhat" for product "Wildfly Core"
7.0.0
Search vendor "Redhat" for product "Wildfly Core" and version "7.0.0"
cr1
Affected
Redhat
Search vendor "Redhat"
Data Grid
Search vendor "Redhat" for product "Data Grid"
7.3.4
Search vendor "Redhat" for product "Data Grid" and version "7.3.4"
-
Affected
Redhat
Search vendor "Redhat"
Jboss Enterprise Application Platform
Search vendor "Redhat" for product "Jboss Enterprise Application Platform"
7.2.4
Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "7.2.4"
-
Affected