CVE-2019-3805
Last modified
CVE-2019-3805 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Enterprise Application Platform | 6.0.0 |
| Redhat | Jboss Enterprise Application Platform | 7.0.0 |
| Redhat | Wildfly | <= 16.0.0 |
References
- https://access.redhat.com/errata/RHSA-2019:1106Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1107Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1108Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1140Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:2413Vendor Advisory
- https://access.redhat.com/errata/RHSA-2020:0727Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3805Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20190517-0004/Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1106Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1107Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1108Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1140Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:2413Vendor Advisory
- https://access.redhat.com/errata/RHSA-2020:0727Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3805Issue Tracking, Vendor Advisory
- https://security.netapp.com/advisory/ntap-20190517-0004/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3805?
How severe is CVE-2019-3805?
How do I fix CVE-2019-3805?
Are you affected by CVE-2019-3805?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
