CVE-2014-0093Redhat Jboss Enterprise Application Platform vulnerability

CWE-26428 documents5 sources
Severity
5.8MEDIUMNVD
EPSS
0.3%
top 48.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 3
Latest updateMay 17

Description

Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.security.AllPermission permission and allows remote attackers to bypass intended access restrictions.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-5655-4wv8-88fx: Red Hat JBoss Enterprise Application Platform (JBEAP) 62022-05-17
CVEList
CVE-2014-0093: Red Hat JBoss Enterprise Application Platform (JBEAP) 62014-04-03

📋Vendor Advisories

1
Red Hat
6: JSM policy not respected by deployed applications2014-02-21

💬Community

24
Bugzilla
CVE-2014-7935 chromium-browser: use-after-free in Speech2015-01-23
Bugzilla
CVE-2014-7943 chromium-browser: out-of-bounds read in Skia2015-01-23
Bugzilla
CVE-2014-7930 chromium-browser: use-after-free in DOM2015-01-23
Bugzilla
CVE-2014-7947 chromium-browser: out-of-bounds read in PDFium2015-01-23
Bugzilla
CVE-2014-7924 chromium-browser: use-after-free in IndexedDB2015-01-23
CVE-2014-0093 — Redhat vulnerability | cvebase