CVE-2020-1748: Red Hat Decision Manager

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

A flaw was found in all supported versions before wildfly-elytron-1.6.8.Final-redhat-00001, where the WildFlySecurityManager checks were bypassed when using custom security managers, resulting in an improper authorization. This flaw leads to information exposure by unauthenticated access to secure resources.

Affected products

  • Red Hat Decision Manager: version 7.0 only
  • Red Hat Process Automation: version 7.0 only
  • Red Hat Wildfly Elytron: before 1.6.8.final-redhat-00001 (fixed in 1.6.8.final-redhat-00001)

Published 2020-09-16. Last modified 2026-06-17.