CVE-2019-3805
MEDIUM severity · CVSS 4.7 · CWE-364
4.7CVSS MEDIUM
Summary
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Impact & exploitability
Attack vectorLocal
Attack complexityHigh
Privileges requiredLow
User interactionNone
Confidentiality impactNone
Integrity impactNone
Availability impactHigh
Exploit probability (EPSS)0%
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- https://access.redhat.com/errata/RHSA-2019:1106Advisory
- https://access.redhat.com/errata/RHSA-2019:1107Advisory
- https://access.redhat.com/errata/RHSA-2019:1108Advisory
- https://access.redhat.com/errata/RHSA-2019:1140Advisory
- https://access.redhat.com/errata/RHSA-2019:2413Advisory
- https://access.redhat.com/errata/RHSA-2020:0727Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3805Advisory
- https://security.netapp.com/advisory/ntap-20190517-0004/Advisory