CVE-2019-14843
07.01.2020, 17:15
A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests for any requester. This flaw could be used by a malicious app deployed on the app server to access unauthorized information and possibly conduct further attacks. Versions shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7 are vulnerable to this issue.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | single_sign-on | 7.3 |
redhat | jboss_enterprise_application_platform | 7.2.0 |
redhat | jboss_enterprise_application_platform | 7.2.0 |
redhat | single_sign-on | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-592 - DEPRECATED: Authentication Bypass IssuesThis weakness has been deprecated because it covered redundant concepts already described in CWE-287.
- CWE-863 - Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.