CVE-2015-0297

Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:jboss_operations_network:3.3.1:*:*:*:*:*:*:*

History

21 Nov 2024, 02:22

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2015-0862.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2015-0862.html - Vendor Advisory
References () http://www.securitytracker.com/id/1032181 - () http://www.securitytracker.com/id/1032181 -

Information

Published : 2015-04-24 14:59

Updated : 2024-11-21 02:22


NVD link : CVE-2015-0297

Mitre link : CVE-2015-0297

CVE.ORG link : CVE-2015-0297


JSON object : View

Products Affected

redhat

  • jboss_operations_network
CWE
CWE-284

Improper Access Control