VYPR
Medium severity4.7NVD Advisory· Published May 3, 2019· Updated Jun 17, 2026

CVE-2019-3805

CVE-2019-3805

Description

A flaw was discovered in wildfly versions up to 16.0.0.Final that would allow local users who are able to execute init.d script to terminate arbitrary processes on the system. An attacker could exploit this by modifying the PID file in /var/run/jboss-eap/ allowing the init.d script to terminate any process as root.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
  • Red Hat/WildFly2 versions
    cpe:2.3:a:redhat:wildfly:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:wildfly:*:*:*:*:*:*:*:*range: <=16.0.0
    • (no CPE)range: affects up to 16.0.0.Final
  • Wildfly/Wildflyllm-fuzzy
    Range: <16.0.0.Final

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.