PT-2013-3554 · Red Hat · Red Hat Jboss Enterprise Application Platform+1

Published

2013-12-06

·

Updated

2019-04-22

·

CVE-2013-2133

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Enterprise Application Platform (EAP) versions prior to 6.2.0
Description The issue concerns the EJB invocation handler implementation in Red Hat JBossWS, which does not properly enforce method level restrictions for JAX-WS Service endpoints. This allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.
Recommendations For versions prior to 6.2.0, update to version 6.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the EJB class and JAX-WS handlers to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-2133
RHSA-2013:1785
RHSA-2013:1786

Affected Products

Red Hat Jboss Enterprise Application Platform
Red Hat Jbossws