CVE-2015-0297

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
24/04/2015
Last modified:
12/04/2025

Description

Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methods via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:jboss_operations_network:3.3.1:*:*:*:*:*:*:*