Back
CVE-2003-0845
Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauthorized activities and possibly execute arbitrary code via certain SQL statements to (1) TCP port 1701 in JBoss 3.2.1, and (2) port 1476 in JBoss 3.0.8.
Published: Nov 17, 2003
Modified: Jun 16, 2026
CWE-89
CVSS Metrics
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| jboss | jboss | 3.0.8 |
| jboss | jboss | 3.2.1 |
GitHub Security Advisory GHSA-6rm7-5fjj-275w
Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms,...
References (14)
- http://marc.info/?l=bugtraq&m=106546044416498&w=2 Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=106547728803252&w=2 Mailing List, Third Party Advisory
- http://secunia.com/advisories/27914 Not Applicable
- http://sourceforge.net/docman/display_doc.php?docid=19314&group_id=22866 Broken Link
- http://www.redhat.com/support/errata/RHSA-2007-1048.html Third Party Advisory
- http://www.securityfocus.com/bid/8773 Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11300 Tool Signature
- http://marc.info/?l=bugtraq&m=106546044416498&w=2 Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=106547728803252&w=2 Mailing List, Third Party Advisory
- http://secunia.com/advisories/27914 Not Applicable
- http://sourceforge.net/docman/display_doc.php?docid=19314&group_id=22866 Broken Link
- http://www.redhat.com/support/errata/RHSA-2007-1048.html Third Party Advisory
- http://www.securityfocus.com/bid/8773 Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11300 Tool Signature
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
15.06%
Top 4% most likely to be exploited
Threat Score
34.5 / 100
Data Sources
NVD
EPSS
GitHub