Lucene search

K
cve[email protected]CVE-2014-7849
HistoryFeb 13, 2015 - 3:59 p.m.

CVE-2014-7849

2015-02-1315:59:05
CWE-264
web.nvd.nist.gov
27
jboss
eap
rbac
access control
cve-2014-7849
security vulnerability

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

6.2 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

67.9%

The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.

Affected configurations

NVD
Node
redhatjboss_enterprise_application_platformMatch6.2.0
OR
redhatjboss_enterprise_application_platformMatch6.2.1
OR
redhatjboss_enterprise_application_platformMatch6.2.2
OR
redhatjboss_enterprise_application_platformMatch6.2.3
OR
redhatjboss_enterprise_application_platformMatch6.2.4
OR
redhatjboss_enterprise_application_platformMatch6.3.0
OR
redhatjboss_enterprise_application_platformMatch6.3.1
OR
redhatjboss_enterprise_application_platformMatch6.3.2

4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

6.2 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

67.9%