CVE-2003-0845 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 15.4% (pctl 97)
Patch early
A public exploit exists.
Description
Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 15.42% — more likely to be exploited than 97% of all CVEs |
| Weakness | CWE-89 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-11-17 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| jboss | jboss |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | JBoss 3.0.8/3.2.1 - HSQLDB Remote Command Injection | 2003-10-06 |
References
- http://marc.info/?l=bugtraq&m=106546044416498&w=2
- http://marc.info/?l=bugtraq&m=106547728803252&w=2
- http://secunia.com/advisories/27914
- http://sourceforge.net/docman/display_doc.php?docid=19314&group_id=22866
- http://www.redhat.com/support/errata/RHSA-2007-1048.html
- http://www.securityfocus.com/bid/8773
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11300
- http://marc.info/?l=bugtraq&m=106546044416498&w=2
- http://marc.info/?l=bugtraq&m=106547728803252&w=2
- http://secunia.com/advisories/27914
- http://sourceforge.net/docman/display_doc.php?docid=19314&group_id=22866
- http://www.redhat.com/support/errata/RHSA-2007-1048.html
- http://www.securityfocus.com/bid/8773
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11300
→ the Explorer · watch your stack · NVD