CVE-2019-14841: High severity red hat decision manager vulnerability
A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.
Other sources
An authenticated attacker can adjust his assigned role in response header, and gain admin access to the app.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this flaw?
The vulnerability ID for this flaw is CVE-2019-14841.
What is the severity of CVE-2019-14841?
CVE-2019-14841 has a severity rating of 8.8 (high).
How can an attacker exploit CVE-2019-14841?
An attacker can exploit CVE-2019-14841 by changing their assigned role in the response header, allowing them to gain admin privileges in the Business Central Console.
Which software versions are affected by CVE-2019-14841?
Redhat Decision Manager 7.0 and Redhat Process Automation 7.0 are affected by CVE-2019-14841.
Is there a fix available for CVE-2019-14841?
Yes, updates are available to fix CVE-2019-14841. Please refer to Red Hat's advisory for more information.