CVE-2014-0093
published 2014-04-03CVE-2014-0093: Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy…
PriorityP434medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
2.10%
79.6th percentile
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.security.AllPermission permission and allows remote attackers to bypass intended access restrictions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
6: JSM policy not respected by deployed applications
vendor_redhat·2014-02-21·CVSS 5.8
CVE-2014-0093 [MEDIUM] 6: JSM policy not respected by deployed applications
6: JSM policy not respected by deployed applications
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.security.AllPermission permission and allows remote attackers to bypass intended access restrictions.
It was found that Java Security Manager permissions configured via a policy file were not properly applied, causing all deployed applications to be granted the java.security.AllPermission permission. In certain cases, an attacker could use this flaw to circumvent expected security measures to perform actions which would otherwise be restricted.
Package: eap (Red Hat JBoss Data Grid 6) - Not affected
Package: eap (Red Hat JB
GHSA
GHSA-5655-4wv8-88fx: Red Hat JBoss Enterprise Application Platform (JBEAP) 6
ghsa_unreviewed·2022-05-17
CVE-2014-0093 [MEDIUM] GHSA-5655-4wv8-88fx: Red Hat JBoss Enterprise Application Platform (JBEAP) 6
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.security.AllPermission permission and allows remote attackers to bypass intended access restrictions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7935 chromium-browser: use-after-free in Speech
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7935 [HIGH] CVE-2014-7935 chromium-browser: use-after-free in Speech
CVE-2014-7935 chromium-browser: use-after-free in Speech
An unspecified use-after-free flaw was found in the Speech component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7943 chromium-browser: out-of-bounds read in Skia
bugzilla·2015-01-23·CVSS 5.0
CVE-2014-7943 [MEDIUM] CVE-2014-7943 chromium-browser: out-of-bounds read in Skia
CVE-2014-7943 chromium-browser: out-of-bounds read in Skia
An unspecified out-of-bounds read flaw was found in the Skia component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7930 chromium-browser: use-after-free in DOM
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7930 [HIGH] CVE-2014-7930 chromium-browser: use-after-free in DOM
CVE-2014-7930 chromium-browser: use-after-free in DOM
An unspecified use-after-free flaw was found in the DOM component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7947 chromium-browser: out-of-bounds read in PDFium
bugzilla·2015-01-23·CVSS 5.0
CVE-2014-7947 [MEDIUM] CVE-2014-7947 chromium-browser: out-of-bounds read in PDFium
CVE-2014-7947 chromium-browser: out-of-bounds read in PDFium
An unspecified out-of-bounds read flaw was found in the PDFium component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7924 chromium-browser: use-after-free in IndexedDB
bugzilla·2015-01-23·CVSS 5.0
CVE-2014-7924 [MEDIUM] CVE-2014-7924 chromium-browser: use-after-free in IndexedDB
CVE-2014-7924 chromium-browser: use-after-free in IndexedDB
An unspecified use-after-free flaw was found in the IndexedDB component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
---
Upstream commit:
https://chromium.googlesource.com/chromium/src/+/2d74497dfa5e6fd6ddddc93248c322a57dd8dd2c
Bugzilla
CVE-2014-7942 chromium-browser: uninitialized-value in Fonts
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7942 [HIGH] CVE-2014-7942 chromium-browser: uninitialized-value in Fonts
CVE-2014-7942 chromium-browser: uninitialized-value in Fonts
An unspecified uninitialized-value flaw was found in the Fonts component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7936 chromium-browser: use-after-free in Views
bugzilla·2015-01-23·CVSS 6.8
CVE-2014-7936 [MEDIUM] CVE-2014-7936 chromium-browser: use-after-free in Views
CVE-2014-7936 chromium-browser: use-after-free in Views
An unspecified use-after-free flaw was found in the Views component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7927 chromium-browser: memory corruption in V8
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7927 [HIGH] CVE-2014-7927 chromium-browser: memory corruption in V8
CVE-2014-7927 chromium-browser: memory corruption in V8
An unspecified memory corruption flaw was found in the V8 component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7941 chromium-browser: out-of-bounds read in UI
bugzilla·2015-01-23·CVSS 5.0
CVE-2014-7941 [MEDIUM] CVE-2014-7941 chromium-browser: out-of-bounds read in UI
CVE-2014-7941 chromium-browser: out-of-bounds read in UI
An unspecified out-of-bounds read flaw was found in the UI component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7929 chromium-browser: use-after-free in DOM
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7929 [HIGH] CVE-2014-7929 chromium-browser: use-after-free in DOM
CVE-2014-7929 chromium-browser: use-after-free in DOM
An unspecified use-after-free flaw was found in the DOM component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7925 chromium-browser: use-after-free in WebAudio
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7925 [HIGH] CVE-2014-7925 chromium-browser: use-after-free in WebAudio
CVE-2014-7925 chromium-browser: use-after-free in WebAudio
An unspecified use-after-free flaw was found in the WebAudio component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7931 chromium-browser: memory corruption in V8
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7931 [HIGH] CVE-2014-7931 chromium-browser: memory corruption in V8
CVE-2014-7931 chromium-browser: memory corruption in V8
An unspecified memory corruption flaw was found in the V8 component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7939 chromium-browser: same-origin-bypass in V8
bugzilla·2015-01-23·CVSS 4.3
CVE-2014-7939 [MEDIUM] CVE-2014-7939 chromium-browser: same-origin-bypass in V8
CVE-2014-7939 chromium-browser: same-origin-bypass in V8
An unspecified same-origin-bypass flaw was found in the V8 component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7938 chromium-browser: memory corruption in Fonts
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7938 [HIGH] CVE-2014-7938 chromium-browser: memory corruption in Fonts
CVE-2014-7938 chromium-browser: memory corruption in Fonts
An unspecified memory corruption flaw was found in the Fonts component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7932 chromium-browser: use-after-free in DOM
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7932 [HIGH] CVE-2014-7932 chromium-browser: use-after-free in DOM
CVE-2014-7932 chromium-browser: use-after-free in DOM
An unspecified use-after-free flaw was found in the DOM component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7944 chromium-browser: out-of-bounds read in PDFium
bugzilla·2015-01-23·CVSS 5.0
CVE-2014-7944 [MEDIUM] CVE-2014-7944 chromium-browser: out-of-bounds read in PDFium
CVE-2014-7944 chromium-browser: out-of-bounds read in PDFium
An unspecified out-of-bounds read flaw was found in the PDFium component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7937 chromium-browser: use-after-free in FFmpeg
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7937 [HIGH] CVE-2014-7937 chromium-browser: use-after-free in FFmpeg
CVE-2014-7937 chromium-browser: use-after-free in FFmpeg
An unspecified use-after-free flaw was found in the FFmpeg component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7928 chromium-browser: memory corruption in V8
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7928 [HIGH] CVE-2014-7928 chromium-browser: memory corruption in V8
CVE-2014-7928 chromium-browser: memory corruption in V8
An unspecified memory corruption flaw was found in the V8 component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7946 chromium-browser: out-of-bounds read in Fonts
bugzilla·2015-01-23·CVSS 5.0
CVE-2014-7946 [MEDIUM] CVE-2014-7946 chromium-browser: out-of-bounds read in Fonts
CVE-2014-7946 chromium-browser: out-of-bounds read in Fonts
An unspecified out-of-bounds read flaw was found in the Fonts component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7945 chromium-browser: out-of-bounds read in PDFium
bugzilla·2015-01-23·CVSS 5.0
CVE-2014-7945 [MEDIUM] CVE-2014-7945 chromium-browser: out-of-bounds read in PDFium
CVE-2014-7945 chromium-browser: out-of-bounds read in PDFium
An unspecified out-of-bounds read flaw was found in the PDFium component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7933 chromium-browser: use-after-free in FFmpeg
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7933 [HIGH] CVE-2014-7933 chromium-browser: use-after-free in FFmpeg
CVE-2014-7933 chromium-browser: use-after-free in FFmpeg
An unspecified use-after-free flaw was found in the FFmpeg component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7934 chromium-browser: use-after-free in DOM
bugzilla·2015-01-23·CVSS 7.5
CVE-2014-7934 [HIGH] CVE-2014-7934 chromium-browser: use-after-free in DOM
CVE-2014-7934 chromium-browser: use-after-free in DOM
An unspecified use-after-free flaw was found in the DOM component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-7948 chromium-browser: caching error in AppCache
bugzilla·2015-01-23·CVSS 4.3
CVE-2014-7948 [MEDIUM] CVE-2014-7948 chromium-browser: caching error in AppCache
CVE-2014-7948 chromium-browser: caching error in AppCache
An unspecified caching error flaw was found in the AppCache component of the Chromium browser.
External References:
http://googlechromereleases.blogspot.com/2015/01/stable-update.html
Discussion:
This issue has been addressed in the following products:
Supplementary for Red Hat Enterprise Linux 6
Via RHSA-2015:0093 https://rhn.redhat.com/errata/RHSA-2015-0093.html
Bugzilla
CVE-2014-0093 JBoss EAP 6: JSM policy not respected by deployed applications
bugzilla·2014-02-26·CVSS 5.8
CVE-2014-0093 [MEDIUM] CVE-2014-0093 JBoss EAP 6: JSM policy not respected by deployed applications
CVE-2014-0093 JBoss EAP 6: JSM policy not respected by deployed applications
IssueDescription:
It was found that Java Security Manager permissions configured via a policy file were not properly applied, causing all deployed applications to be granted the java.security.AllPermission permission. In certain cases, an attacker could use this flaw to circumvent expected security measures to perform actions which would otherwise be restricted.
Discussion:
Acknowledgements:
This issue was discovered by Josef Cacek of the Red Hat JBoss EAP Quality Engineering team.
---
This issue has been addressed in following products:
Red Hat JBoss Enterprise Application Platform 6.2.2
Via RHSA-2014:0345 https://rhn.redhat.com/errata/RHSA-2014-0345.html
---
This issue has been addressed in following
http://rhn.redhat.com/errata/RHSA-2014-0343.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0344.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0345.htmlhttp://secunia.com/advisories/57675http://www.securityfocus.com/bid/66596http://rhn.redhat.com/errata/RHSA-2014-0343.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0344.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0345.htmlhttp://secunia.com/advisories/57675http://www.securityfocus.com/bid/66596
2014-04-03
Published