Description
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. NOTE: this issue was originally reported for ESB Runtime 3.5.1, but it originates in MMC.
Exploits (1)
References (4)
Core 4
Core References
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Oct/107
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Oct/98
Exploit x_refsource_misc
http://packetstormsecurity.com/files/128799
Vendor Advisory x_refsource_confirm
http://www.mulesoft.org/documentation/display/current/Mule+Enterprise+Management+Console+Security+Update
Scores
EPSS
0.1512
EPSS Percentile
94.6%
Details
CWE
CWE-264
Status
published
Products (1)
mulesoft/mule_enterprise_management_console
Published
Nov 20, 2014
Tracked Since
Feb 18, 2026