CVE-2019-14841

HIGH

Red Hat Decision Manager - Authenticated Privilege Escalation via Role Modification in Response Header

Title source: llm
STIX 2.1

Description

A flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attacker to gain admin privileges in the Business Central Console.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0034
EPSS Percentile 56.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-281
Status published
Products (2)
redhat/decision_manager 7.0
redhat/process_automation 7.0
Published Oct 17, 2022
Tracked Since Feb 18, 2026