Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-7849

Опубликовано: 11 фев. 2015
Источник: redhat
CVSS2: 4.9
EPSS Низкий

Описание

The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.

It was discovered that the Role Based Access Control (RBAC) implementation did not sufficiently verify all authorization conditions that are required by the Maintainer role to perform certain administrative actions. An authenticated user with the Maintainer role could use this flaw to add, modify, or undefine a limited set of attributes and their values, which otherwise cannot be written to.

Отчет

This issue did not affect the versions of Red Hat JBoss Enterprise Application Platform before 6.2.0 as they did not include support for role-based access control (RBAC).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 6SecurityAffected
Red Hat JBoss Enterprise Application Platform 5SecurityNot affected
Red Hat JBoss Enterprise Web Server 1othersUnder investigation
Red Hat JBoss Portal 6SecurityAffected
Red Hat JBoss Enterprise Application Platform 6.3FixedRHSA-2015:021511.02.2015
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5antlr-eap6FixedRHSA-2015:021611.02.2015
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5apache-cxfFixedRHSA-2015:021611.02.2015
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5glassfish-jsf-eap6FixedRHSA-2015:021611.02.2015
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5guava-librariesFixedRHSA-2015:021611.02.2015
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5hibernate4-eap6FixedRHSA-2015:021611.02.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=1165170Management: Limited RBAC authorization bypass

EPSS

Процентиль: 60%
0.004
Низкий

4.9 Medium

CVSS2

Связанные уязвимости

nvd
почти 11 лет назад

The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.

github
больше 3 лет назад

The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.

EPSS

Процентиль: 60%
0.004
Низкий

4.9 Medium

CVSS2