First published: Tue Jul 07 2020(Updated: )
It was found that the issue for security flaw <a href="https://access.redhat.com/security/cve/CVE-2019-3805">CVE-2019-3805</a> appeared again in a further version of JBoss Enterprise Application Platform - Continuous Delivery (EAP-CD) introducing regression. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Enterprise Application Platform | ||
Redhat Wildfly |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14317.
Redhat Jboss Enterprise Application Platform and Redhat Wildfly are affected.
The severity of CVE-2020-14317 is medium.
The CWE ID for this vulnerability is 364.
An attacker can exploit CVE-2020-14317 by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to perform arbitrary commands.