CVE-2014-8120
Summary
| CVE | CVE-2014-8120 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-12-18 15:59:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The agent in Thermostat before 1.0.6, when using unspecified configurations, allows local users to obtain the JMX management URLs of all local Java virtual machines and gain privileges via unknown vectors. |
Risk And Classification
Primary CVSS: v2.0 4.4 from [email protected]
AV:L/AC:M/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Thermostat Project | Thermostat | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [Thermostat-announce] [SECURITY UPDATE] Thermostat 1.0.6 update released! | af854a3a-2127-422b-91ae-364da2661108 | icedtea.classpath.org | Patch |
| Red Hat Customer Portal | MITRE | access.redhat.com | |
| CVE-2014-8120 - Red Hat Customer Portal | MITRE | access.redhat.com | |
| 1168977 – (CVE-2014-8120) CVE-2014-8120 thermostat: local JMX URL disclosure | MITRE | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.