PT-2015-3932 · Red Hat · Red Hat Jboss Enterprise Application Platform

Published

2015-02-13

·

Updated

2017-09-08

·

CVE-2014-7849

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions JBoss Enterprise Application Platform (EAP) versions 6.2.0 through 6.3.2
Description The Role Based Access Control (RBAC) implementation does not properly verify authorization conditions. This allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.
Recommendations For JBoss Enterprise Application Platform (EAP) versions 6.2.0 through 6.3.2, consider restricting access to the Maintainer role until a proper fix is applied to ensure that authorization conditions are properly verified.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7849
RHSA-2015:0216
RHSA-2015:0217
RHSA-2015:0218

Affected Products

Red Hat Jboss Enterprise Application Platform