{"api_version":"1","generated_at":"2026-07-23T12:02:34+00:00","cve":"CVE-2014-8115","urls":{"html":"https://cve.report/CVE-2014-8115","api":"https://cve.report/api/cve/CVE-2014-8115.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-8115","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-8115"},"summary":{"title":"CVE-2014-8115","description":"The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspecified impact via unknown vectors.","state":"PUBLISHED","assigner":"redhat","published_at":"2015-02-20 16:59:03","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://github.com/droolsjbpm/kie-wb-distributions/commit/90eed433d3","name":"https://github.com/droolsjbpm/kie-wb-distributions/commit/90eed433d3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BZ(1169544,1169556,1169557,1169559,1169560,1169545,1169566,1169565,11… · kiegroup/kie-wb-distributions@90eed43 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0235.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0235.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0234.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0234.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-8115","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-8115","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"8115","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"kie_workbench","cpe6":"6.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"8115","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"kie_workbench","cpe6":"6.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T13:10:51.043Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2015:0234","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0234.html"},{"name":"RHSA-2015:0235","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0235.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/droolsjbpm/kie-wb-distributions/commit/90eed433d3"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-12-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspecified impact via unknown vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2015-02-20T15:57:00.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2015:0234","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0234.html"},{"name":"RHSA-2015:0235","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0235.html"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/droolsjbpm/kie-wb-distributions/commit/90eed433d3"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2014-8115","datePublished":"2015-02-20T16:00:00.000Z","dateReserved":"2014-10-10T00:00:00.000Z","dateUpdated":"2024-08-06T13:10:51.043Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2015-02-20 16:59:03","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:kie_workbench:6.0.0:*:*:*:*:*:*:*","matchCriteriaId":"780D9EFD-2FE7-4F86-B4F7-035E92B4A336"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:kie_workbench:6.0.1:*:*:*:*:*:*:*","matchCriteriaId":"52224639-65FA-4BBD-A09E-DB05E202741A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"8115","Ordinal":"1","Title":"CVE-2014-8115","CVE":"CVE-2014-8115","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"8115","Ordinal":"1","NoteData":"The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspecified impact via unknown vectors.","Type":"Description","Title":"CVE-2014-8115"},{"CveYear":"2014","CveId":"8115","Ordinal":"2","NoteData":"2015-02-20","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"8115","Ordinal":"3","NoteData":"2015-02-20","Type":"Other","Title":"Modified"}]}}}