Fedora Account System
Red Hat Associate
Red Hat Customer
A remote user authenticated as administrative user can inject a malformed payload into the Inet Address field, that is accessible via the Management Model. Once the management interface is successfully modified, the server crashes and cannot be recovered (not even by a Super User) because the payload is written into the standalone.xml configuration file. Manual removal of the injected date from the file is required in order to bring the server back online.