CVE-2013-6448
Summary
| CVE | CVE-2013-6448 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-01-23 00:55:03 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote attackers to bypass the WebRemote annotation restriction and obtain information about arbitrary classes and methods on the server classpath via unspecified vectors. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS: 0.002620000 probability, percentile 0.495200000 (date 2026-05-03)
Problem Types: CWE-264 | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Jboss Seam 2 Framework | 2.0.0 | beta1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.0.0 | cr1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.0.0 | cr2 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.0.0 | cr3 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.0.0 | ga | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.0.1 | cr1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.0.1 | cr2 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.0.1 | ga | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.0.2 | cr1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.0.2 | cr2 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.0.2 | ga | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.0.2 | sp1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.0.3 | cr1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.1.0 | alpha1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.1.0 | beta1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.1.0 | cr1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.1.0 | ga | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.1.0 | sp1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.1.1 | cr1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.1.1 | cr2 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.1.1 | ga | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.1.2 | All | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.1.2 | cr1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.1.2 | cr2 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.2.0 | cr1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.2.0 | ga | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.2.1 | All | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.2.1 | cr1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.2.1 | cr2 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.2.1 | cr3 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.2.2 | All | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.3.0 | All | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.3.0 | alpha | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.3.0 | beta1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.3.0 | beta2 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.3.0 | cr1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | 2.3.1 | cr1 | All | All |
| Application | Redhat | Jboss Seam 2 Framework | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| https://issues.jboss.org/browse/WFK2-375 enhanced fix · seam2/jboss-seam@090aa62 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| 1044794 – (CVE-2013-6448) CVE-2013-6448 JBoss Seam: Information disclosure in remoting | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Patch, Vendor Advisory |
| JBoss Web Framework Kit Lets Remote Users Obtain Potentially Sensitive Information - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.