CVE-2020-14317: Medium severity jboss enterprise application platform vulnerability
Published Jul 7, 2020
·Updated
It was found that the issue for security flaw CVE-2019-3805 appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Affected Software
2 affected components
redhat JBoss Enterprise Application Platform
redhat Wildfly
Event History
Jul 7, 2020
Data Sourced
12:23 AM
DescriptionSeverityAffected Software
Jun 2, 2021
CVE Published
via MITRE·11:27 AM
Data Sourced
via MITRE·11:27 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security flaw?
The vulnerability ID is CVE-2020-14317.
2
What software is affected by this vulnerability?
Redhat Jboss Enterprise Application Platform and Redhat Wildfly are affected.
3
What is the severity of CVE-2020-14317?
The severity of CVE-2020-14317 is medium.
4
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The CWE ID for this vulnerability is 364.
5
How can an attacker exploit CVE-2020-14317?
An attacker can exploit CVE-2020-14317 by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to perform arbitrary commands.