CVE-2013-2133
published 2013-12-06CVE-2013-2133: The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce…
PriorityP428medium5.5CVSS 2.0
AVNACLAuSCPIPAN
EPSS
1.81%
76.2th percentile
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | jboss_enterprise_application_platform | <= 6.1.0 | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jm2h-vv8x-8cv3: The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6
ghsa_unreviewed·2022-05-17·CVSS 5.5
CVE-2014-3464 [MEDIUM] GHSA-jm2h-vv8x-8cv3: The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2133.
GHSA
GHSA-2579-mjx2-r625: The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6
ghsa_unreviewed·2022-05-14
CVE-2013-2133 [MEDIUM] GHSA-2579-mjx2-r625: The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.
Red Hat
WS: Incomplete fix for CVE-2013-2133
vendor_redhat·2014-08-06·CVSS 5.5
CVE-2014-3464 [MEDIUM] WS: Incomplete fix for CVE-2013-2133
WS: Incomplete fix for CVE-2013-2133
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0, does not properly enforce the method level restrictions for outbound messages, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2133.
It was found that the fix for CVE-2013-2133 was incomplete: the JAX-WS handlers were being executed for outbound messages even when authorization had failed. A remote attacker who is authorized to access the EJB class, could invoke a JAX-WS handler which they were not authorized to invoke.
Red Hat
WS: EJB3 role restrictions are not applied to jaxws handlers
vendor_redhat·2013-12-04·CVSS 5.5
CVE-2013-2133 [MEDIUM] CWE-862 WS: EJB3 role restrictions are not applied to jaxws handlers
WS: EJB3 role restrictions are not applied to jaxws handlers
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.
A flaw was found in the way method-level authorization for JAX-WS Service endpoints was performed by the EJB invocation handler implementation. Any restrictions declared on EJB methods were ignored when executing the JAX-WS handlers, and only class-level restrictions were applied. A remote attacker who is authorized to access the EJB class, could invoke a JAX-WS handler which they were
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3464 JBoss WS: Incomplete fix for CVE-2013-2133
bugzilla·2014-05-28·CVSS 5.5
CVE-2014-3464 [MEDIUM] CVE-2014-3464 JBoss WS: Incomplete fix for CVE-2013-2133
CVE-2014-3464 JBoss WS: Incomplete fix for CVE-2013-2133
IssueDescription:
It was found that the fix for CVE-2013-2133 was incomplete: the JAX-WS handlers were being executed for outbound messages even when authorization had failed. A remote attacker who is authorized to access the EJB class, could invoke a JAX-WS handler which they were not authorized to invoke.
Discussion:
Acknowledgement:
This issue was discovered by Tomas Kyjovsky of the Red Hat Quality Engineering Team.
---
This issue has been addressed in following products:
JBoss Enterprise Application Platform 6.3.0
Via RHSA-2014:1021 https://rhn.redhat.com/errata/RHSA-2014-1021.html
---
This issue has been addressed in following products:
JBEAP 6 for RHEL 6
Via RHSA-2014:1020 https://rhn.redhat.com/errata/RHSA-2014-10
Bugzilla
CVE-2013-2133 JBoss WS: EJB3 role restrictions are not applied to jaxws handlers
bugzilla·2013-06-03·CVSS 5.5
CVE-2013-2133 [MEDIUM] CVE-2013-2133 JBoss WS: EJB3 role restrictions are not applied to jaxws handlers
CVE-2013-2133 JBoss WS: EJB3 role restrictions are not applied to jaxws handlers
A vulnerability was identified in the way in which method-level authorization for JAX-WS Service endpoints was performed by the EJB invocation handler implementation. Any restrictions declared on EJB methods were ignored when executing the JAX-WS handlers and only class-level restrictions were applied. A remote attacker who is authorized to access the EJB class, could invoke a JAX-WS handler that they are not authorized to.
Discussion:
Acknowledgements:
This issue was discovered by Richard Opalka and Arun Neelicattu of Red Hat.
---
This issue has been addressed in following products:
Red Hat JBoss Enterprise Application Platform 6.2.0
Via RHSA-2013:1784 https://rhn.redhat.com/errata/RHSA-2013-1784.html
http://rhn.redhat.com/errata/RHSA-2013-1784.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1785.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1786.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://www.securitytracker.com/id/1029431http://rhn.redhat.com/errata/RHSA-2013-1784.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1785.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1786.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://www.securitytracker.com/id/1029431
2013-12-06
Published