Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-7853

Опубликовано: 11 фев. 2015
Источник: redhat
CVSS2: 4.9
EPSS Низкий

Описание

The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging access to the security-domain attribute.

It was discovered that the JBoss Application Server (WildFly) JacORB subsystem incorrectly assigned socket-binding-ref sensitivity classification for the security-domain attribute. An authenticated user with a role that has access to attributes with socket-binding-ref and not security-domain-ref sensitivity classification could use this flaw to access sensitive information present in the security-domain attribute.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 6jacorbAffected
Red Hat JBoss Enterprise Application Platform 5SecurityNot affected
Red Hat JBoss Enterprise Web Server 1othersUnder investigation
Red Hat JBoss Portal 6jacorbAffected
Red Hat JBoss Enterprise Application Platform 6.3FixedRHSA-2015:021511.02.2015
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5antlr-eap6FixedRHSA-2015:021611.02.2015
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5apache-cxfFixedRHSA-2015:021611.02.2015
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5glassfish-jsf-eap6FixedRHSA-2015:021611.02.2015
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5guava-librariesFixedRHSA-2015:021611.02.2015
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 5hibernate4-eap6FixedRHSA-2015:021611.02.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-284->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1165522Subsystem: Information disclosure via incorrect sensitivity classification of attribute

EPSS

Процентиль: 62%
0.00428
Низкий

4.9 Medium

CVSS2

Связанные уязвимости

nvd
почти 11 лет назад

The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging access to the security-domain attribute.

github
больше 3 лет назад

The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging access to the security-domain attribute.

EPSS

Процентиль: 62%
0.00428
Низкий

4.9 Medium

CVSS2