ID |
CVE-2020-14299
|
Sažetak |
A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an attacker to perform a complete authentication bypass by using an arbitrary user and password. The highest threat to vulnerability is to system availability. |
Reference |
|
CVSS |
Base: | 6.3 |
Impact: | 6.9 |
Exploitability: | 6.8 |
|
Pristup |
Vektor | Složenost | Autentikacija |
NETWORK |
MEDIUM |
SINGLE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
NONE |
NONE |
COMPLETE |
|
CVSS vektor |
AV:N/AC:M/Au:S/C:N/I:N/A:C |
Zadnje važnije ažuriranje |
27-10-2020 - 19:19 |
Objavljeno |
16-10-2020 - 14:15 |