peter bassill · operator
$ cve CVE-2019-7727 JSON

CVE-2019-7727

9.8
CRITICAL · CVSS 3.0 · EPSS 3.9% (pctl 90)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol by using the JMX connector. The observed affected TCP port is 6338 but, based on the product's configuration, a different one could be vulnerable.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.87% — more likely to be exploited than 90% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2019-04-23
Last modified2026-06-17

Affected (1)

VendorProduct
niceengage

References

→ the Explorer  ·  watch your stack  ·  NVD