Vulnerability Name: | CVE-2014-7849 (CCN-100890) | ||||||||
Assigned: | 2014-10-03 | ||||||||
Published: | 2015-02-11 | ||||||||
Updated: | 2017-09-08 | ||||||||
Summary: | The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role. | ||||||||
CVSS v3 Severity: | 3.5 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N) 3.0 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2014-7849 Source: CCN Type: RHSA-2015-0215 Moderate: Red Hat JBoss Enterprise Application Platform 6.3.3 update Source: REDHAT Type: Vendor Advisory RHSA-2015:0215 Source: REDHAT Type: Vendor Advisory RHSA-2015:0216 Source: REDHAT Type: Vendor Advisory RHSA-2015:0217 Source: REDHAT Type: Vendor Advisory RHSA-2015:0218 Source: REDHAT Type: Vendor Advisory RHSA-2015:0920 Source: CCN Type: SECTRACK ID: 1031741 Red Hat JBoss Enterprise Application Platform Bugs Let Remote Users Obtain Potentially Sensitive Information and Remote Authenticated Users Bypass Security Controls Source: CCN Type: Red Hat Web site JBoss Enterprise Application Platform Source: SECTRACK Type: UNKNOWN 1031741 Source: CONFIRM Type: Vendor Advisory https://bugzilla.redhat.com/show_bug.cgi?id=1165170 Source: XF Type: UNKNOWN redhat-jboss-cve20147849-sec-bypass(100890) Source: XF Type: UNKNOWN redhat-jboss-cve20147849-sec-bypass(100890) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |