CVE-2014-7849
published 2015-02-13CVE-2014-7849: The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization…
PriorityP420medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.26%
66.3th percentile
The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5938-95q9-6rh3: The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6
ghsa_unreviewed·2022-05-17
CVE-2014-7849 [MEDIUM] GHSA-5938-95q9-6rh3: The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6
The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.
Red Hat
Management: Limited RBAC authorization bypass
vendor_redhat·2015-02-11·CVSS 4.0
CVE-2014-7849 [MEDIUM] CWE-863 Management: Limited RBAC authorization bypass
Management: Limited RBAC authorization bypass
The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.
It was discovered that the Role Based Access Control (RBAC) implementation did not sufficiently verify all authorization conditions that are required by the Maintainer role to perform certain administrative actions. An authenticated user with the Maintainer role could use this flaw to add, modify, or undefine a limited set of attributes and their values, which otherwise cannot be written to.
Statement: This issue did not affect the versions
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-0215.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0216.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0217.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0218.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0920.htmlhttp://www.securitytracker.com/id/1031741https://bugzilla.redhat.com/show_bug.cgi?id=1165170https://exchange.xforce.ibmcloud.com/vulnerabilities/100890http://rhn.redhat.com/errata/RHSA-2015-0215.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0216.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0217.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0218.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0920.htmlhttp://www.securitytracker.com/id/1031741https://bugzilla.redhat.com/show_bug.cgi?id=1165170https://exchange.xforce.ibmcloud.com/vulnerabilities/100890
2015-02-13
Published