VulnerabilityModified
CVE-2021-20250
The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on the server it is deployed on.
MEDIUM 4.3EPSS 0.74%
Does this matter?
Lower severity and a low EPSS score (0.74%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on the server it is deployed on. The highest threat from this vulnerability is to data confidentiality.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.74% probability · 53th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- redhat/jboss-ejb-client · redhat/jboss enterprise application platform expansion pack
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1929479Issue Tracking, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1929479Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.