CVE-2003-0845

Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:jboss:jboss:3.0.8:*:*:*:*:*:*:*
cpe:2.3:a:jboss:jboss:3.2.1:*:*:*:*:*:*:*

History

20 Nov 2024, 23:45

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=106546044416498&w=2 - Mailing List, Third Party Advisory () http://marc.info/?l=bugtraq&m=106546044416498&w=2 - Mailing List, Third Party Advisory
References () http://marc.info/?l=bugtraq&m=106547728803252&w=2 - Mailing List, Third Party Advisory () http://marc.info/?l=bugtraq&m=106547728803252&w=2 - Mailing List, Third Party Advisory
References () http://secunia.com/advisories/27914 - Not Applicable () http://secunia.com/advisories/27914 - Not Applicable
References () http://sourceforge.net/docman/display_doc.php?docid=19314&group_id=22866 - Broken Link () http://sourceforge.net/docman/display_doc.php?docid=19314&group_id=22866 - Broken Link
References () http://www.redhat.com/support/errata/RHSA-2007-1048.html - Third Party Advisory () http://www.redhat.com/support/errata/RHSA-2007-1048.html - Third Party Advisory
References () http://www.securityfocus.com/bid/8773 - Patch, Third Party Advisory, VDB Entry, Vendor Advisory () http://www.securityfocus.com/bid/8773 - Patch, Third Party Advisory, VDB Entry, Vendor Advisory
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11300 - Tool Signature () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11300 - Tool Signature

Information

Published : 2003-11-17 05:00

Updated : 2024-11-20 23:45


NVD link : CVE-2003-0845

Mitre link : CVE-2003-0845

CVE.ORG link : CVE-2003-0845


JSON object : View

Products Affected

jboss

  • jboss
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')