CVE-2014-7849

JBoss Enterprise Application Platform 6.2.0-6.3.2 - Authenticated Attribute Manipulation via RBAC Bypass

Title source: llm
STIX 2.1

Description

The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.

References (8)

Core 8
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0920.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/100890
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0215.html
Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1165170
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0217.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0218.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2015-0216.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031741

Scores

EPSS 0.0126
EPSS Percentile 66.5%

Details

CWE
CWE-264
Status published
Products (8)
redhat/jboss_enterprise_application_platform 6.2.0
redhat/jboss_enterprise_application_platform 6.2.1
redhat/jboss_enterprise_application_platform 6.2.2
redhat/jboss_enterprise_application_platform 6.2.3
redhat/jboss_enterprise_application_platform 6.2.4
redhat/jboss_enterprise_application_platform 6.3.0
redhat/jboss_enterprise_application_platform 6.3.1
redhat/jboss_enterprise_application_platform 6.3.2
Published Feb 13, 2015
Tracked Since Feb 18, 2026