CVE-2014-0005

PicketBox/JBossSX <6.2.2-6.0.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

PicketBox and JBossSX, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2 and JBoss BRMS before 6.0.3 roll up patch 2, allows remote authenticated users to read and modify the application sever configuration and state by deploying a crafted application.

References (6)

Core 6
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0720.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0345.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0234.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0235.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0344.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-0343.html

Scores

EPSS 0.0080
EPSS Percentile 52.7%

Details

CWE
CWE-264
Status published
Products (2)
redhat/jboss_enterprise_application_platform 6.2.2
redhat/jboss_enterprise_brms_platform < 6.0.3
Published Feb 20, 2015
Tracked Since Feb 18, 2026