CVE-2014-3472
published 2014-08-19CVE-2014-3472: The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP)…
PriorityP425medium4.9CVSS 2.0
AVNACMAuSCPIPAN
EPSS
1.68%
74.4th percentile
The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:N
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x926-v8v9-j4mp: The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBE
ghsa_unreviewed·2022-05-17
CVE-2014-3472 [MEDIUM] GHSA-x926-v8v9-j4mp: The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBE
The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors.
Red Hat
Security: Invalid EJB caller role check implementation
vendor_redhat·2014-08-06·CVSS 4.9
CVE-2014-3472 [MEDIUM] CWE-184 Security: Invalid EJB caller role check implementation
Security: Invalid EJB caller role check implementation
The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors.
It was found that the isCallerInRole() method of the SimpleSecurityManager did not correctly check caller roles. A remote, authenticated attacker could use this flaw to circumvent the caller check in applications that use black list access control based on caller roles.
Package: jboss-as-controller (Red Hat JBoss Data Grid 6) - Not affected
Package: jboss-as-controller (Red Hat JBoss Data Virtualization 6) - Not affected
Package: security (Re
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2014-1019.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://www.securityfocus.com/bid/69094https://bugzilla.redhat.com/show_bug.cgi?id=1103815https://exchange.xforce.ibmcloud.com/vulnerabilities/95170http://rhn.redhat.com/errata/RHSA-2014-1019.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://www.securityfocus.com/bid/69094https://bugzilla.redhat.com/show_bug.cgi?id=1103815https://exchange.xforce.ibmcloud.com/vulnerabilities/95170
2014-08-19
Published