vulnerability

Red Hat JBoss EAP: CVE-2023-4503: Improper Initialization

Severity
8
CVSS
(AV:N/AC:M/Au:S/C:C/I:C/A:N)
Published
Dec 4, 2023
Added
Sep 19, 2024
Modified
Mar 25, 2026

Description

An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.. An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.

Solution

red-hat-jboss-eap-upgrade-latest

References

    Title
    Rapid7 Labs

    2026 Global Threat Landscape Report

    The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.