CVE-2014-8115
KIE Workbench 6.0.x - Authenticated Arbitrary File Read and Write
Title source: llmDescription
The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspecified impact via unknown vectors.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0234.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0235.html
Patch x_refsource_confirm
https://github.com/droolsjbpm/kie-wb-distributions/commit/90eed433d3
Scores
EPSS
0.0191
EPSS Percentile
77.6%
Details
CWE
CWE-264
Status
published
Products (2)
redhat/kie_workbench
6.0.0
redhat/kie_workbench
6.0.1
Published
Feb 20, 2015
Tracked Since
Feb 18, 2026