Multiple Red Hat JBoss Products Local Security Bypass Vulnerability
BID:65591
Info
Multiple Red Hat JBoss Products Local Security Bypass Vulnerability
| Bugtraq ID: | 65591 |
| Class: | Design Error |
| CVE: |
CVE-2014-0018 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 13 2014 12:00AM |
| Updated: | Dec 19 2014 12:53AM |
| Credit: | Stuart Douglas of Red Hat. |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Multiple Red Hat JBoss Products Local Security Bypass Vulnerability
JBoss Enterprise Application Platform and JBoss WildFly Application Server are prone to a local security bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the MSC service registry of affected application, this may lead to further attacks.
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 is vulnerable; other versions may also be affected.
JBoss Enterprise Application Platform and JBoss WildFly Application Server are prone to a local security bypass vulnerability.
An attacker can exploit this issue to gain unauthorized access to the MSC service registry of affected application, this may lead to further attacks.
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 is vulnerable; other versions may also be affected.
Exploit / POC
Multiple Red Hat JBoss Products Local Security Bypass Vulnerability
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Multiple Red Hat JBoss Products Local Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information
Solution:
Updates are available. Please see the references or vendor advisory for more information
References
Multiple Red Hat JBoss Products Local Security Bypass Vulnerability
References:
References: