CVE-2003-0845 describes an unknown vulnerability within the HSQLDB component of JBoss versions 3.2.1 and 3.0.8, specifically when running on Java 1.4.x platforms in their default configurations. This flaw allows remote attackers to execute unauthorized activities and potentially arbitrary code through crafted SQL statements sent to specific TCP ports (1701 for JBoss 3.2.1 and 1476 for JBoss 3.0.8). With a CVSS score of 7.5, it is considered highly severe due to its network-based attack vector, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog and showing no active community discussion or media coverage, an exploit for remote command injection is publicly available on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.8CPE matchmatch criteria | cpe:2.3:a:jboss:jboss:3.0.8:*:*:*:*:*:*:* | ||
3.2.1CPE matchmatch criteria | cpe:2.3:a:jboss:jboss:3.2.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.