CVE-2014-7853
published 2015-02-13CVE-2014-7853: The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign…
PriorityP416medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.24%
65.8th percentile
The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging access to the security-domain attribute.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | <= 6.3.2 | — |
| redhat | jboss_operations_network | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7cr6-g5pc-g6g4: The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6
ghsa_unreviewed·2022-05-17
CVE-2014-7853 [MEDIUM] CWE-200 GHSA-7cr6-g5pc-g6g4: The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6
The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging access to the security-domain attribute.
Red Hat
Subsystem: Information disclosure via incorrect sensitivity classification of attribute
vendor_redhat·2015-02-11·CVSS 4.0
CVE-2014-7853 [MEDIUM] CWE-284 Subsystem: Information disclosure via incorrect sensitivity classification of attribute
Subsystem: Information disclosure via incorrect sensitivity classification of attribute
The JBoss Application Server (WildFly) JacORB subsystem in Red Hat JBoss Enterprise Application Platform (EAP) before 6.3.3 does not properly assign socket-binding-ref sensitivity classification to the security-domain attribute, which allows remote authenticated users to obtain sensitive information by leveraging access to the security-domain attribute.
It was discovered that the JBoss Application Server (WildFly) JacORB subsystem incorrectly assigned socket-binding-ref sensitivity classification for the security-domain attribute. An authenticated user with a role that has access to attributes with socket-binding-ref and not security-domain-ref sensitivity classification could use this flaw to access
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-0215.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0216.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0217.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0218.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0920.htmlhttp://www.securitytracker.com/id/1031741https://exchange.xforce.ibmcloud.com/vulnerabilities/100891http://rhn.redhat.com/errata/RHSA-2015-0215.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0216.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0217.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0218.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0920.htmlhttp://www.securitytracker.com/id/1031741https://exchange.xforce.ibmcloud.com/vulnerabilities/100891
2015-02-13
Published