CVE-2019-3834

HIGH

JBoss Operations Network 3.2.1-3.3.10 - Unsafe Reflection via ClassLoader Manipulation

Title source: llm
STIX 2.1

Description

It was found that the fix for CVE-2014-0114 had been reverted in JBoss Operations Network 3 (JON). This flaw allows attackers to manipulate ClassLoader properties on a vulnerable server. Exploits that have been published rely on ClassLoader properties that are exposed such as those in JON 3. Additional information can be found in the Red Hat Knowledgebase article: https://access.redhat.com/site/solutions/869353. Note that while multiple products released patches for the original CVE-2014-0114 flaw, the reversion described by this CVE-2019-3834 flaw only occurred in JON 3.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3834

Scores

CVSS v3 7.3
EPSS 0.0033
EPSS Percentile 56.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-470
Status published
Products (1)
redhat/jboss_operations_network 3.2.1 - 3.3.11
Published Oct 03, 2019
Tracked Since Feb 18, 2026