The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://rhn.redhat.com/errata/RHSA-2015-0920.html | vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/100890 | vdb entry |
http://rhn.redhat.com/errata/RHSA-2015-0215.html | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1165170 | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0217.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0218.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0216.html | vendor advisory |
http://www.securitytracker.com/id/1031741 | vdb entry |