CVE-2014-8175: Medium severity red hat jboss fuse vulnerability
It was found that JBoss Fuse would allow any user defined in the users.properties file to access the HawtIO console without having a valid admin role. This could allow a remote attacker to bypass intended authentication HawtIO console access restrictions.
Other sources
Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8175?
CVE-2014-8175 is classified as a high severity vulnerability due to unauthorized access potential.
How do I fix CVE-2014-8175?
To fix CVE-2014-8175, upgrade to JBoss Fuse version 6.2.0 or higher.
What software is affected by CVE-2014-8175?
CVE-2014-8175 affects Red Hat JBoss Fuse versions prior to 6.2.0.
What exploit does CVE-2014-8175 enable?
CVE-2014-8175 allows remote attackers to access the HawtIO console without valid admin credentials.
Can CVE-2014-8175 be exploited remotely?
Yes, CVE-2014-8175 can be exploited remotely due to inadequate access controls.