{"api_version":"1","generated_at":"2026-07-23T18:56:26+00:00","cve":"CVE-2014-3472","urls":{"html":"https://cve.report/CVE-2014-3472","api":"https://cve.report/api/cve/CVE-2014-3472.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-3472","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-3472"},"summary":{"title":"CVE-2014-3472","description":"The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors.","state":"PUBLISHED","assigner":"redhat","published_at":"2014-08-19 18:55:01","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.9","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:N","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1103815","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1103815","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bug 1103815 – CVE-2014-3472 JBoss AS Security: Invalid EJB caller role check implementation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95170","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95170","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-1021.html","name":"http://rhn.redhat.com/errata/RHSA-2014-1021.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/69094","name":"http://www.securityfocus.com/bid/69094","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-1020.html","name":"http://rhn.redhat.com/errata/RHSA-2014-1020.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0720.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0720.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2014-1019.html","name":"http://rhn.redhat.com/errata/RHSA-2014-1019.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-3472","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3472","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"3472","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"jboss_enterprise_application_platform","cpe6":"6.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2014-3472","qid":"241029","title":"Red Hat Update for JBoss Enterprise Application Platform 6.3.0 (RHSA-2014:1020)"},{"cve":"CVE-2014-3472","qid":"241030","title":"Red Hat Update for JBoss Enterprise Application Platform 6.3.0 (RHSA-2014:1019)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:43:06.286Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2015:0720","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0720.html"},{"name":"RHSA-2014:1020","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1020.html"},{"name":"69094","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/69094"},{"name":"RHSA-2014:1021","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1021.html"},{"name":"RHSA-2014:1019","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1019.html"},{"name":"jboss-cve20143472-sec-bypass(95170)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95170"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1103815"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-08-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2015:0720","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0720.html"},{"name":"RHSA-2014:1020","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1020.html"},{"name":"69094","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/69094"},{"name":"RHSA-2014:1021","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1021.html"},{"name":"RHSA-2014:1019","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2014-1019.html"},{"name":"jboss-cve20143472-sec-bypass(95170)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/95170"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1103815"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2014-3472","datePublished":"2014-08-19T18:00:00.000Z","dateReserved":"2014-05-14T00:00:00.000Z","dateUpdated":"2024-08-06T10:43:06.286Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-08-19 18:55:01","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:N","baseScore":4.9,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.3.0:*:*:*:*:*:*:*","matchCriteriaId":"A69B5EA1-06B9-4FAC-A4D7-F1C444D00880"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"3472","Ordinal":"1","Title":"CVE-2014-3472","CVE":"CVE-2014-3472","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"3472","Ordinal":"1","NoteData":"The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors.","Type":"Description","Title":"CVE-2014-3472"},{"CveYear":"2014","CveId":"3472","Ordinal":"2","NoteData":"2014-08-19","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"3472","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}