CVE Vulnerabilities

CVE-2014-3464

Published: Aug 19, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2133.

Affected Software

Name Vendor Start Version End Version
Jboss_enterprise_application_platform Redhat 6.2.0 (including) 6.2.0 (including)
Jboss_enterprise_application_platform Redhat 6.3.0 (including) 6.3.0 (including)

References