CVE-2014-7827
published 2015-02-13CVE-2014-7827: The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3…
PriorityP418low3.5CVSS 2.0
AVNACMAuSCNIPAN
EPSS
1.74%
75.2th percentile
The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authenticated users to bypass intended access restrictions by leveraging credentials on the default domain for a role that is also on the application domain.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | <= 6.3.2 | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Security: Wrong security context loaded when using SAML2 STS Login Module
vendor_redhat·2015-02-11·CVSS 3.5
CVE-2014-7827 [LOW] CWE-863 Security: Wrong security context loaded when using SAML2 STS Login Module
Security: Wrong security context loaded when using SAML2 STS Login Module
The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authenticated users to bypass intended access restrictions by leveraging credentials on the default domain for a role that is also on the application domain.
It was found that when processing undefined security domains, the org.jboss.security.plugins.mapping.JBossMappingManager implementation would fall back to the default security domain if it was available. A user with valid credentials in the defined default domain, with a role that is valid in the expected applicati
GHSA
GHSA-hgx6-q6mp-88m2: The org
ghsa_unreviewed·2022-05-17
CVE-2014-7827 [LOW] GHSA-hgx6-q6mp-88m2: The org
The org.jboss.security.plugins.mapping.JBossMappingManager implementation in JBoss Security in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 uses the default security domain when a security domain is undefined, which allows remote authenticated users to bypass intended access restrictions by leveraging credentials on the default domain for a role that is also on the application domain.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-0215.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0216.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0217.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0218.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://www.securitytracker.com/id/1031741https://exchange.xforce.ibmcloud.com/vulnerabilities/100889http://rhn.redhat.com/errata/RHSA-2015-0215.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0216.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0217.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0218.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0850.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0851.htmlhttp://www.securitytracker.com/id/1031741https://exchange.xforce.ibmcloud.com/vulnerabilities/100889
2015-02-13
Published