Lucene search

K
prionPRIOn knowledge basePRION:CVE-2020-14299
HistoryOct 16, 2020 - 2:15 p.m.

Authentication flaw

2020-10-1614:15:00
PRIOn knowledge base
www.prio-n.com
8

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.8%

A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an attacker to perform a complete authentication bypass by using an arbitrary user and password. The highest threat to vulnerability is to system availability.

6.6 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

29.8%