Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3472

Опубликовано: 06 авг. 2014
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors.

It was found that the isCallerInRole() method of the SimpleSecurityManager did not correctly check caller roles. A remote, authenticated attacker could use this flaw to circumvent the caller check in applications that use black list access control based on caller roles.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 6jboss-as-controllerNot affected
Red Hat JBoss Data Virtualization 6jboss-as-controllerNot affected
Red Hat JBoss Enterprise Application Platform 5securityNot affected
Red Hat JBoss Enterprise Web Server 1othersNot affected
Red Hat JBoss Operations Network 3jboss-as-controllerNot affected
Red Hat JBoss BPMS 6.0jboss-as-controllerFixedRHSA-2015:023417.02.2015
Red Hat JBoss BRMS 6.0jboss-as-controllerFixedRHSA-2015:023517.02.2015
Red Hat JBoss Enterprise Application Platform 6.3FixedRHSA-2014:102106.08.2014
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-commons-beanutils-eap6FixedRHSA-2014:101906.08.2014
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-commons-cli-eap6FixedRHSA-2014:101906.08.2014

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-184
https://bugzilla.redhat.com/show_bug.cgi?id=1103815Security: Invalid EJB caller role check implementation

EPSS

Процентиль: 47%
0.00241
Низкий

2.1 Low

CVSS2

Связанные уязвимости

nvd
больше 11 лет назад

The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors.

github
больше 3 лет назад

The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors.

EPSS

Процентиль: 47%
0.00241
Низкий

2.1 Low

CVSS2