peter bassill · operator
$ cve CVE-2003-0845 JSON

CVE-2003-0845 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 15.4% (pctl 97)

Patch early

A public exploit exists.

Description

Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS15.42% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-89
On CISA KEVno
Public exploityes
Published2003-11-17
Last modified2026-06-16

Affected (1)

VendorProduct
jbossjboss

Public exploits

SourceTitleDate
exploit-dbJBoss 3.0.8/3.2.1 - HSQLDB Remote Command Injection2003-10-06

References

→ the Explorer  ·  watch your stack  ·  NVD