Vulnerability Name: | CVE-2014-3472 (CCN-95170) | ||||||||
Assigned: | 2014-08-06 | ||||||||
Published: | 2014-08-06 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.9 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N) 3.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-3472 Source: REDHAT Type: Vendor Advisory RHSA-2014:1019 Source: REDHAT Type: Vendor Advisory RHSA-2014:1020 Source: REDHAT Type: Vendor Advisory RHSA-2014:1021 Source: REDHAT Type: Vendor Advisory RHSA-2015:0720 Source: BID Type: UNKNOWN 69094 Source: CCN Type: BID-69094 JBoss AS Security CVE-2014-3472 Security Bypass Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 1103815 (CVE-2014-3472) CVE-2014-3472 JBoss AS Security: Invalid EJB caller role check implementation Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=1103815 Source: XF Type: UNKNOWN jboss-cve20143472-sec-bypass(95170) Source: XF Type: UNKNOWN jboss-cve20143472-sec-bypass(95170) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |