Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Mulesoft Subscribe
Filtered by product Mule Enterprise Management Console
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-9000 1 Mulesoft 1 Mule Enterprise Management Console 2014-11-20 6.5 MEDIUM N/A
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. NOTE: this issue was originally reported for ESB Runtime 3.5.1, but it originates in MMC.