CVE-2014-7827
LOW severity · CVSS 3.5 · CWE-264
3.5CVSS LOW
Summary
The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authenticated users to bypass intended access restrictions by leveraging credentials on the default domain for a role that is also on the application domain.
Impact & exploitability
Attack vectorNetwork
Attack complexity—
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impact—
Availability impactNone
Exploit probability (EPSS)2%
AV:N/AC:M/Au:S/C:N/I:P/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://rhn.redhat.com/errata/RHSA-2015-0215.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2015-0216.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2015-0217.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2015-0218.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2015-0850.html
- http://rhn.redhat.com/errata/RHSA-2015-0851.html
- http://www.securitytracker.com/id/1031741
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100889