First published: Tue Dec 18 2018(Updated: )
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Enterprise Application Platform | =6.0.0 | |
Redhat Jboss Enterprise Application Platform | =7.0.0 | |
Redhat Wildfly | <=16.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-3805 is medium.
Redhat Jboss Enterprise Application Platform 6.0.0 is affected by CVE-2019-3805.
Redhat Jboss Enterprise Application Platform 7.0.0 is affected by CVE-2019-3805.
Redhat Wildfly up to version 16.0.0 is affected by CVE-2019-3805.
An attacker can exploit CVE-2019-3805 by modifying the PID file in /var/run/jboss-eap/ to allow the init.d script to terminate arbitrary processes on the system.