CVE-2014-3472 - CERT CVE
ID CVE-2014-3472
Sažetak The isCallerInRole function in SimpleSecurityManager in JBoss Application Server (AS) 7, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 6.3.0, does not properly check caller roles, which allows remote authenticated users to bypass access restrictions via unspecified vectors.
Reference
CVSS
Base: 4.9
Impact: 4.9
Exploitability:6.8
Pristup
VektorSloženostAutentikacija
NETWORK MEDIUM SINGLE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL NONE
CVSS vektor AV:N/AC:M/Au:S/C:P/I:P/A:N
Zadnje važnije ažuriranje 29-08-2017 - 01:34
Objavljeno 19-08-2014 - 18:55