PT-2014-3475 · Red Hat · Red Hat Jboss Enterprise Application Platform

Publicado

2014-04-03

·

Atualizado

2017-01-07

·

CVE-2014-0093

CVSS v2.0

5.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Enterprise Application Platform (JBEAP) version 6.2.2
Description The issue is related to the improper application of permissions defined by a policy file when using a Java Security Manager (JSM). This causes applications to be granted the java.security.AllPermission permission, allowing remote attackers to bypass intended access restrictions.
Recommendations For Red Hat JBoss Enterprise Application Platform (JBEAP) version 6.2.2, consider updating the policy file to properly restrict permissions and ensure the Java Security Manager (JSM) is correctly configured to enforce these restrictions. As a temporary workaround, restrict access to sensitive applications and resources to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-0093
RHSA-2014:0343
RHSA-2014:0344

Produtos afetados

Red Hat Jboss Enterprise Application Platform