Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/8773 | Patch Third Party Advisory VDB Entry Vendor Advisory |
http://sourceforge.net/docman/display_doc.php?docid=19314&group_id=22866 | Broken Link |
http://www.redhat.com/support/errata/RHSA-2007-1048.html | Third Party Advisory |
http://secunia.com/advisories/27914 | Not Applicable |
http://marc.info/?l=bugtraq&m=106547728803252&w=2 | Mailing List Third Party Advisory |
http://marc.info/?l=bugtraq&m=106546044416498&w=2 | Mailing List Third Party Advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11300 | Tool Signature |
Configurations
Configuration 1 (hide)
|
Information
Published : 2003-11-16 21:00
Updated : 2020-03-24 07:57
NVD link : CVE-2003-0845
Mitre link : CVE-2003-0845
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
jboss
- jboss