Medium severity4.9NVD Advisory· Published Oct 14, 2019· Updated Jun 17, 2026
CVE-2019-14838
CVE-2019-14838
Description
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.wildfly.core:wildfly-host-controllerMaven | < 7.2.5.GA | 7.2.5.GA |
Affected products
16- Red Hat/wildfly-corev5Range: before 7.2.5.GA
cpe:2.3:a:redhat:wildfly_core:7.0.0:-:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:redhat:wildfly_core:7.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:redhat:wildfly_core:7.0.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:redhat:wildfly_core:7.0.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:redhat:wildfly_core:7.0.0:alpha3:*:*:*:*:*:*
- cpe:2.3:a:redhat:wildfly_core:7.0.0:alpha4:*:*:*:*:*:*
- cpe:2.3:a:redhat:wildfly_core:7.0.0:alpha5:*:*:*:*:*:*
- cpe:2.3:a:redhat:wildfly_core:7.0.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:redhat:wildfly_core:7.0.0:cr1:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.5:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.4:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:single_sign-on:7.3.5:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
16- access.redhat.com/errata/RHSA-2019:3082nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3083nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4018nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4019nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4020nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4021nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4040nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4041nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4042nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:4045nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0728nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-82v2-f875-73g9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-14838ghsaADVISORY
- github.com/wildfly/wildfly-core/commit/131fa6880ae1523fac9e96df54dc394b63b0eed3ghsaWEB
- github.com/wildfly/wildfly-core/pull/3981ghsaWEB
News mentions
0No linked articles in our index yet.