CVE-2023-4503
CVE-2023-4503 is a medium-severity vulnerability in Redhat Jboss Enterprise Application Platform with a CVSS 3.x base score of 6.8. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-665.
Key facts
- Severity: Medium (CVSS 3.x base score 6.8)
- EPSS exploit prediction: 1% (51st percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2023-54358
- Weakness: CWE-665
- Affected product: Redhat Jboss Enterprise Application Platform
- Published:
- Last modified:
Description
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.
Frequently asked questions
- What is CVE-2023-4503?
- An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.
- How severe is CVE-2023-4503?
- CVE-2023-4503 has a CVSS 3.x base score of 6.8, rated medium severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability none.
- Is CVE-2023-4503 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (51st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2023-4503?
- CVE-2023-4503 primarily affects Redhat Jboss Enterprise Application Platform. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2023-4503?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2023-4503 have an EU (EUVD) identifier?
- Yes. CVE-2023-4503 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2023-54358.
- When was CVE-2023-4503 published?
- CVE-2023-4503 was published on 2024-02-06 and last updated on 2026-06-17.
References
- https://access.redhat.com/errata/RHSA-2023:7637
- https://access.redhat.com/errata/RHSA-2023:7638
- https://access.redhat.com/errata/RHSA-2023:7639
- https://access.redhat.com/errata/RHSA-2023:7641
- https://access.redhat.com/security/cve/CVE-2023-4503
- https://bugzilla.redhat.com/show_bug.cgi?id=2184751
Affected products (3)
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*
More vulnerabilities in Redhat Jboss Enterprise Application Platform
- CVE-2018-14721 — Critical (CVSS 10.0): FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF)…
- CVE-2019-14892 — Critical (CVSS 9.8): A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit…
- CVE-2019-17531 — Critical (CVSS 9.8): A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is…
- CVE-2019-17267 — Critical (CVSS 9.8): A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to…
- CVE-2019-10212 — Critical (CVSS 9.8): A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an…
- CVE-2019-16943 — Critical (CVSS 9.8): A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is…
All CVEs affecting Redhat Jboss Enterprise Application Platform →
Other CWE-665 (Improper Initialization) vulnerabilities
- CVE-2024-38558 — Critical (CVSS 10.0): In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix overwriting ct original…
- CVE-2026-64775 — Critical (CVSS 9.8): A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS…
- CVE-2024-46697 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: nfsd: ensure that nfsd4_fattr_args.context is…
- CVE-2021-33635 — Critical (CVSS 9.8): When malicious images are pulled by isula pull, attackers can execute arbitrary code.
- CVE-2022-37128 — Critical (CVSS 9.8): In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end.
- CVE-2021-41264 — Critical (CVSS 9.8): OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using…
Browse all CWE-665 (Improper Initialization) vulnerabilities →