CVE-2015-0297: Critical severity red hat jboss operations network vulnerability
Published Apr 24, 2015
·Updated
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.
Affected Software
1 affected component
redhat JBoss Operations Network=3.3.1
Event History
Apr 24, 2015
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0297?
CVE-2015-0297 has been classified as a critical severity vulnerability.
2
How do I fix CVE-2015-0297?
To fix CVE-2015-0297, upgrade to Red Hat JBoss Operations Network version 3.3.2 or later.
3
What type of attacks can exploit CVE-2015-0297?
CVE-2015-0297 can be exploited to execute arbitrary Java methods or cause denial of service through disk consumption.
4
Which version of Red Hat JBoss Operations Network is affected by CVE-2015-0297?
Red Hat JBoss Operations Network version 3.3.1 is affected by CVE-2015-0297.
5
Is remote access required to exploit CVE-2015-0297?
Yes, CVE-2015-0297 allows remote attackers to exploit the vulnerability without authentication.