CVE-2023-4503
MEDIUMDescription
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.
Is your site exposed to CVE-2023-4503?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| redhat | jboss_enterprise_application_platform |
| redhat | jboss_enterprise_application_platform_expansion_pack |
| redhat | jboss_enterprise_application_platform |
| redhat | enterprise_linux |
| redhat | enterprise_linux |
| redhat | enterprise_linux |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-4503? +
How severe is CVE-2023-4503? +
What products are affected by CVE-2023-4503? +
How do I check if I'm vulnerable to CVE-2023-4503? +
Related Vulnerabilities
Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an information …
The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vulnerability exists in the version …
An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending …
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, …
The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via …
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following …