{"id":"CVE-2019-14838","details":"A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server","aliases":["GHSA-82v2-f875-73g9"],"modified":"2026-07-07T08:50:06.385606565Z","published":"2019-10-14T15:15:09.710Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:redhat:data_grid:7.3.4:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.3.4"},{"last_affected":"7.3.4"}],"source":"CPE_STRING","vendor_product":"redhat:data_grid"},{"cpes":["cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.4:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.5:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.2.0"},{"last_affected":"7.2.0"},{"introduced":"7.2.5"},{"last_affected":"7.2.5"},{"introduced":"7.3.0"},{"last_affected":"7.3.0"},{"introduced":"7.2.4"},{"last_affected":"7.2.4"}],"source":"CPE_STRING","vendor_product":"redhat:jboss_enterprise_application_platform"},{"extracted_events":[{"introduced":"7.3.5"},{"last_affected":"7.3.5"}],"source":"CPE_STRING","vendor_product":"redhat:single_sign-on","cpes":["cpe:2.3:a:redhat:single_sign-on:7.3.5:*:*:*:*:*:*:*"]},{"cpes":["cpe:2.3:a:redhat:wildfly_core:7.0.0:alpha3:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0.0-alpha3"},{"last_affected":"7.0.0-alpha3"}],"source":"CPE_STRING","vendor_product":"redhat:wildfly_core"}]},"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3082"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3083"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4018"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4019"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4020"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4021"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4040"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4041"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4042"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:4045"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2020:0728"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14838"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wildfly/wildfly-core","events":[{"introduced":"500b3ba2aca8301c086004e45af1d108afdc32ea"},{"last_affected":"85f2a6adfe830c33aaa1c7eaafb212b34ce6121c"}],"database_specific":{"cpe":["cpe:2.3:a:redhat:wildfly_core:7.0.0:-:*:*:*:*:*:*","cpe:2.3:a:redhat:wildfly_core:7.0.0:alpha1:*:*:*:*:*:*","cpe:2.3:a:redhat:wildfly_core:7.0.0:alpha2:*:*:*:*:*:*","cpe:2.3:a:redhat:wildfly_core:7.0.0:alpha4:*:*:*:*:*:*","cpe:2.3:a:redhat:wildfly_core:7.0.0:alpha5:*:*:*:*:*:*","cpe:2.3:a:redhat:wildfly_core:7.0.0:beta1:*:*:*:*:*:*","cpe:2.3:a:redhat:wildfly_core:7.0.0:cr1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0.0-NA"},{"last_affected":"7.0.0-NA"},{"introduced":"7.0.0-alpha1"},{"last_affected":"7.0.0-alpha1"},{"introduced":"7.0.0-alpha2"},{"last_affected":"7.0.0-alpha2"},{"introduced":"7.0.0-alpha4"},{"last_affected":"7.0.0-alpha4"},{"introduced":"7.0.0-alpha5"},{"last_affected":"7.0.0-alpha5"},{"introduced":"7.0.0-beta1"},{"last_affected":"7.0.0-beta1"},{"introduced":"7.0.0-cr1"},{"last_affected":"7.0.0-cr1"}],"source":"CPE_STRING"}}],"versions":["7.0.0-NA","7.0.0-alpha1","7.0.0-alpha2","7.0.0-alpha4","7.0.0-alpha5","7.0.0-beta1","7.0.0-cr1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-14838.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"}]}