PT-2015-3933 · Red Hat+1 · Red Hat Jboss Enterprise Application Platform+2

Publicado

2015-02-13

·

Atualizado

2017-09-08

·

CVE-2014-7853

CVSS v2.0

4.0

Média

VetorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Enterprise Application Platform (EAP) versions prior to 6.3.3
Description The issue affects the JBoss Application Server (WildFly) JacORB subsystem, where it fails to properly assign socket-binding-ref sensitivity classification to the security-domain attribute. This allows remote authenticated users to obtain sensitive information by accessing the security-domain attribute.
Recommendations For versions prior to 6.3.3, update to version 6.3.3 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-7853
RHSA-2015:0216
RHSA-2015:0217
RHSA-2015:0218

Produtos afetados

Jboss Application Server
Jacorb
Red Hat Jboss Enterprise Application Platform