CVE-2014-3700: Critical severity red hat edeploy vulnerability
Published Nov 21, 2019
·Updated
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
Affected Software
3 affected components
debian
redhat Edeploy<=1.6.0
redhat Jboss Enterprise Web Server=1.0.0
Event History
Nov 21, 2019
CVE Published
via MITRE·02:31 PM
Data Sourced
via MITRE·02:31 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2014-3700?
CVE-2014-3700 is a vulnerability in eDeploy that allows remote code execution.
2
How severe is CVE-2014-3700?
CVE-2014-3700 has a severity rating of critical with a score of 9.8.
3
What software versions are affected by CVE-2014-3700?
CVE-2014-3700 affects Redhat Edeploy version 1.6.0, Redhat Jboss Enterprise Web Server version 1.0.0, and Debian packages.
4
How does CVE-2014-3700 allow remote code execution?
CVE-2014-3700 allows remote code execution through the use of eval() function with untrusted data.
5
Where can I find more information about CVE-2014-3700?
You can find more information about CVE-2014-3700 at the following references: [Bugzilla Redhat](https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-3700) and [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2014-3700).