First published: Thu Aug 22 2019(Updated: )
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Decision Manager | =7.0 | |
Redhat Process Automation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this flaw is CVE-2019-14841.
CVE-2019-14841 has a severity rating of 8.8 (high).
An attacker can exploit CVE-2019-14841 by changing their assigned role in the response header, allowing them to gain admin privileges in the Business Central Console.
Redhat Decision Manager 7.0 and Redhat Process Automation 7.0 are affected by CVE-2019-14841.
Yes, updates are available to fix CVE-2019-14841. Please refer to Red Hat's advisory for more information.