CVE-2015-0297
Last modified
CVE-2015-0297 is a vulnerability of currently unknown severity. Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.. EPSS estimates a 2.20% chance of exploitation in the next 30 days.
Description
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Operations Network | 3.3.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-0297?
How severe is CVE-2015-0297?
How do I fix CVE-2015-0297?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-0291The sigalgs implementation in t1_lib.c in OpenSSL 1.0.2 befo…
- CVE-2015-0292Integer underflow in the EVP_DecodeUpdate function in crypto…
- CVE-2015-0293The SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 be…
- CVE-2015-0294GnuTLS before 3.3.13 does not validate that the signature al…7.5
- CVE-2015-0295The BMP decoder in QtGui in QT before 5.5 does not properly …
- CVE-2015-0296The pre-install script in texlive 3.1.20140525_r34255.fc21 a…
- CVE-2015-0298Cross-site scripting (XSS) vulnerability in the manager web …
- CVE-2015-0299Multiple cross-site scripting (XSS) vulnerabilities in Open …
- CVE-2015-0300Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2015-0301Adobe Flash Player before 13.0.0.260 and 14.x through 16.x b…
- CVE-2015-0302Adobe Flash Player before 13.0.0.260 and 14.x through 16.x b…
- CVE-2015-0303Adobe Flash Player before 13.0.0.260 and 14.x through 16.x b…
Are you affected by CVE-2015-0297?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
