CVE Vulnerabilities

CVE-2014-8120

Published: Dec 18, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.4 MEDIUM
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.6 IMPORTANT
AV:L/AC:L/Au:N/C:C/I:C/A:N
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The agent in Thermostat before 1.0.6, when using unspecified configurations, allows local users to obtain the JMX management URLs of all local Java virtual machines and gain privileges via unknown vectors.

Affected Software

NameVendorStart VersionEnd Version
ThermostatThermostat_project*1.0.4 (including)
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6RedHatthermostat1-thermostat-0:1.0.4-60.6.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.4 EUSRedHatthermostat1-thermostat-0:1.0.4-60.6.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.5 EUSRedHatthermostat1-thermostat-0:1.0.4-60.6.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 6.6 EUSRedHatthermostat1-thermostat-0:1.0.4-60.6.el6*
Red Hat Software Collections 1 for Red Hat Enterprise Linux 7RedHatthermostat1-thermostat-0:1.0.4-70.6.el7*

References