Authorization Flaw in Wildfly Security Manager Affects Red Hat JBoss EAP and SSO
CVE-2019-14843
7.5HIGH
What is CVE-2019-14843?
An authorization flaw exists in Wildfly Security Manager when running under JDK 11 or 8, allowing any requester to authorize requests. This vulnerability permits malicious applications hosted on the app server to access sensitive information and may lead to additional attacks. Specifically, Red Hat JBoss EAP 7 and Red Hat SSO 7 installations are susceptible to this issue, raising concerns about unauthorized data access.
Affected Version(s)
wildfly-security-manager As shipped with Red Hat Jboss EAP 7 and Red Hat SSO 7