Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:15963
HistoryMay 02, 2019 - 5:06 a.m.

Authorization Bypass

2019-05-0205:06:12
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.002 Low

EPSS

Percentile

58.7%

JBoss AS is vulnerable to authorization bypass. The isCallerInRole() method of the SimpleSecurityManager did not correctly check caller roles. A remote, authenticated attacker could use this flaw to circumvent the caller check in applications that use black list access control based on caller roles.

References

0.002 Low

EPSS

Percentile

58.7%

Related for VERACODE:15963