The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authenticated users to bypass intended access restrictions by leveraging credentials on the default domain for a role that is also on the application domain.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://rhn.redhat.com/errata/RHSA-2015-0850.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0215.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0851.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0217.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0218.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0216.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/100889 | vdb entry |
http://www.securitytracker.com/id/1031741 | vdb entry |