Back to search
CVE-2014-9000
Published: Nov 20, 2014
Modified: Sep 16, 2024
PUBLISHED
Description
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows remote authenticated users to gain administrator privileges and execute arbitrary code via a crafted request that adds a new user. NOTE: this issue was originally reported for ESB Runtime 3.5.1, but it originates in MMC.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20141024 Re: Mulesoft ESB Authenticated Privilege Escalation
mailing-list
x_refsource_FULLDISC
20141022 Mulesoft ESB Authenticated Privilege Escalation
mailing-list
x_refsource_FULLDISC
http://packetstormsecurity.com/files/128799
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now