CVE-2014-3518: Code Injection
jmx-remoting.sar in JBoss Remoting, as used in Red Hat JBoss Enterprise Application Platform (JEAP) 5.2.0, Red Hat JBoss BRMS 5.3.1, Red Hat JBoss Portal Platform 5.2.2, and Red Hat JBoss SOA Platform 5.3.1, does not properly implement the JSR 160 specification, which allows remote attackers to execute arbitrary code via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3518?
CVE-2014-3518 is considered to be of high severity due to its potential to allow remote code execution.
How do I fix CVE-2014-3518?
To fix CVE-2014-3518, upgrade to the latest versions of affected JBoss products as recommended by Red Hat.
Which versions are affected by CVE-2014-3518?
CVE-2014-3518 affects JBoss Enterprise Application Platform 5.2.0, JBoss BRMS 5.3.1, JBoss Portal 5.2.2, and JBoss SOA Platform 5.3.1.
Can CVE-2014-3518 be exploited remotely?
Yes, CVE-2014-3518 can be exploited remotely by attackers due to improper implementation of the JSR 160 specification.
What should I do if I am using an affected version related to CVE-2014-3518?
If you are using an affected version related to CVE-2014-3518, you should prioritize upgrading to a patched version to mitigate the vulnerability.