CVE-2014-0005

개요

It was identified that PicketBox/JBossSX allowed any deployed application to alter or read the underlying application server configuration and state without any authorization checks. An attacker able to deploy applications could use this flaw to circumvent security constraints applied to other applications deployed on the same system, disclose privileged information, and in certain cases allow arbitrary code execution.

CVSS (Common Vulnerability Scoring System) 점수 세부 사항

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v2 점수 분석

Red HatNVDcve.org
기본 점수3.63.6N/A
공격 벡터LocalLocalN/A
액세스 복잡성LowLowN/A
인증NoneNoneN/A
기밀성에 미치는 영향PartialPartialN/A
무결성에 미치는 영향PartialPartialN/A
가용성에 미치는 영향NoneNoneN/A

벡터

Red Hat: AV:L/AC:L/Au:N/C:P/I:P/A:N

NVD: AV:L/AC:L/Au:N/C:P/I:P/A:N

취약점 이해 (CWE)

Confidentiality

Technical Impact: Read Application Data; Read Files or Directories

An attacker could read sensitive data, either by reading the data directly from a data store that is not restricted, or by accessing insufficiently-protected, privileged functionality to read the data.

Integrity

Technical Impact: Modify Application Data; Modify Files or Directories

An attacker could modify sensitive data, either by writing the data directly to a data store that is not restricted, or by accessing insufficiently-protected, privileged functionality to write the data.

Access Control

Technical Impact: Gain Privileges or Assume Identity; Bypass Protection Mechanism

An attacker could gain privileges by modifying or reading critical data directly, or by accessing privileged functionality.

Availability

Technical Impact: DoS: Crash, Exit, or Restart; DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)

An attacker could gain unauthorized access to resources on the system and excessively consume those resources, leading to a denial of service.

감사의 말

This issue was discovered by Josef Cacek (Red Hat JBoss EAP Quality Engineering team).

자주하는 질문

에라타 알림을 받으시겠습니까? 여기에서 등록하세요.