CVE-2014-3464

Red Hat JBoss Enterprise Application Platform 6.2.0 and 6.3.0 - Authenticated JAX-WS Handler Access Bypass

Title source: llm
STIX 2.1

Description

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2133.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/95409
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1020.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1102317
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1021.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1019.html

Scores

EPSS 0.0109
EPSS Percentile 61.8%

Details

CWE
CWE-264
Status published
Products (2)
redhat/jboss_enterprise_application_platform 6.2.0
redhat/jboss_enterprise_application_platform 6.3.0
Published Aug 19, 2014
Tracked Since Feb 18, 2026