SB2015021305 - Permissions, Privileges, and Access Controls in JBoss Enterprise Application Platform
Published: February 13, 2015 Updated: August 9, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2014-7849)
The vulnerability allows a remote #AU# to manipulate data.
The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.
Remediation
Install update from vendor's website.
References
- http://rhn.redhat.com/errata/RHSA-2015-0215.html
- http://rhn.redhat.com/errata/RHSA-2015-0216.html
- http://rhn.redhat.com/errata/RHSA-2015-0217.html
- http://rhn.redhat.com/errata/RHSA-2015-0218.html
- http://rhn.redhat.com/errata/RHSA-2015-0920.html
- http://www.securitytracker.com/id/1031741
- https://bugzilla.redhat.com/show_bug.cgi?id=1165170
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100890