Medium severity6.8NVD Advisory· Published Feb 6, 2024· Updated Jun 17, 2026
CVE-2023-4503
CVE-2023-4503
Description
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- Red Hat/EAP 7.4.14v5cpe:/a:redhat:jboss_enterprise_application_platform:7.4
cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7+ 4 more
- cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7range: 0:7.4.14-5.GA_redhat_00002.1.el7eap
- cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8range: 0:7.4.14-5.GA_redhat_00002.1.el8eap
- cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9range: 0:7.4.14-5.GA_redhat_00002.1.el9eap
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*
cpe:/a:redhat:jbosseapxp+ 1 more
- cpe:/a:redhat:jbosseapxp
- cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- access.redhat.com/errata/RHSA-2023:7637nvdVendor Advisory
- access.redhat.com/errata/RHSA-2023:7638nvdVendor Advisory
- access.redhat.com/errata/RHSA-2023:7639nvdVendor Advisory
- access.redhat.com/errata/RHSA-2023:7641nvdVendor Advisory
- access.redhat.com/security/cve/CVE-2023-4503nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
News mentions
0No linked articles in our index yet.