Confidentiality Disclosure in Red Hat AMQ 7.8 Management Console
CVE-2021-3763 Published on August 23, 2022

A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality as this flaw means some role bindings are incorrectly checked, some privileged meta information such as queue names and configuration details are disclosed but the impact is limited as not all information is accessible and there is no affect to integrity.

NVD

Weakness Type

What is an AuthZ Vulnerability?

The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

CVE-2021-3763 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2021-3763

stack.watch emails you whenever new vulnerabilities are published in Red Hat Amq Broker or Red Hat Amq. Just hit a watch button to start following.

 
 

Exploit Probability

EPSS
0.17%
Percentile
37.41%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.