Lucene search

K
cveRedhatCVE-2014-3518
HistoryJul 22, 2014 - 8:55 p.m.

CVE-2014-3518

2014-07-2220:55:01
CWE-94
redhat
web.nvd.nist.gov
33
jboss
remoting
vulnerability
jeap
brms
nvd
cve-2014-3518

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8

Confidence

Low

EPSS

0.01

Percentile

83.6%

jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Portal Platform 5.2.2, and Red Hat JBoss SOA Platform 5.3.1, does not properly implement the JSR 160 specification, which allows remote attackers to execute arbitrary code via unspecified vectors.

Affected configurations

Nvd
Node
redhatjboss_enterprise_application_platformMatch5.2.0
OR
redhatjboss_enterprise_brms_platformMatch5.3.1
OR
redhatjboss_enterprise_portal_platformMatch5.2.2
OR
redhatjboss_enterprise_soa_platformMatch5.3.1
VendorProductVersionCPE
redhatjboss_enterprise_application_platform5.2.0cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.2.0:*:*:*:*:*:*:*
redhatjboss_enterprise_brms_platform5.3.1cpe:2.3:a:redhat:jboss_enterprise_brms_platform:5.3.1:*:*:*:*:*:*:*
redhatjboss_enterprise_portal_platform5.2.2cpe:2.3:a:redhat:jboss_enterprise_portal_platform:5.2.2:*:*:*:*:*:*:*
redhatjboss_enterprise_soa_platform5.3.1cpe:2.3:a:redhat:jboss_enterprise_soa_platform:5.3.1:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8

Confidence

Low

EPSS

0.01

Percentile

83.6%

Related for CVE-2014-3518