CVE-2014-3472
Summary
| CVE | CVE-2014-3472 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-19 18:55:00 UTC |
| Updated | 2017-08-29 01:34:00 UTC |
| Description | The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors. |
NVD Known Affected Configurations (CPE 2.3)
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 241029 Red Hat Update for JBoss Enterprise Application Platform 6.3.0 (RHSA-2014:1020)
- 241030 Red Hat Update for JBoss Enterprise Application Platform 6.3.0 (RHSA-2014:1019)