CVE Vulnerabilities

CVE-2014-7849

Published: Feb 13, 2015 | Modified: Sep 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.

Affected Software

Name Vendor Start Version End Version
Jboss_enterprise_application_platform Redhat 6.2.4 6.2.4
Jboss_enterprise_application_platform Redhat 6.3.2 6.3.2
Jboss_enterprise_application_platform Redhat 6.2.1 6.2.1
Jboss_enterprise_application_platform Redhat 6.3.1 6.3.1
Jboss_enterprise_application_platform Redhat 6.2.0 6.2.0
Jboss_enterprise_application_platform Redhat 6.2.2 6.2.2
Jboss_enterprise_application_platform Redhat 6.3.0 6.3.0
Jboss_enterprise_application_platform Redhat 6.2.3 6.2.3

References