PT-2015-3933 · Red Hat+1 · Red Hat Jboss Enterprise Application Platform+2

Published

2015-02-13

·

Updated

2017-09-08

·

CVE-2014-7853

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Enterprise Application Platform (EAP) versions prior to 6.3.3
Description The issue affects the JBoss Application Server (WildFly) JacORB subsystem, where it fails to properly assign socket-binding-ref sensitivity classification to the security-domain attribute. This allows remote authenticated users to obtain sensitive information by accessing the security-domain attribute.
Recommendations For versions prior to 6.3.3, update to version 6.3.3 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7853
RHSA-2015:0216
RHSA-2015:0217
RHSA-2015:0218

Affected Products

Jboss Application Server
Jacorb
Red Hat Jboss Enterprise Application Platform