PT-2015-3932 · Red Hat · Red Hat Jboss Enterprise Application Platform

Publicado

2015-02-13

·

Atualizado

2017-09-08

·

CVE-2014-7849

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions JBoss Enterprise Application Platform (EAP) versions 6.2.0 through 6.3.2
Description The Role Based Access Control (RBAC) implementation does not properly verify authorization conditions. This allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.
Recommendations For JBoss Enterprise Application Platform (EAP) versions 6.2.0 through 6.3.2, consider restricting access to the Maintainer role until a proper fix is applied to ensure that authorization conditions are properly verified.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-7849
RHSA-2015:0216
RHSA-2015:0217
RHSA-2015:0218

Produtos afetados

Red Hat Jboss Enterprise Application Platform