CVE-2014-0093
6: JSM policy not respected by deployed applications
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.security.AllPermission permission and allows remote attackers to bypass intended access restrictions.
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, cuando utiliza un Java Security Manager (JSM), no aplica debidamente permisos definidos por un archivo de polĂtica, lo que causa a aplicaciones ser concedidas el permiso java.security.AllPermission y permite a atacantes remotos evadir restricciones de acceso.
It was found that Java Security Manager permissions configured via a policy file were not properly applied, causing all deployed applications to be granted the java.security.AllPermission permission. In certain cases, an attacker could use this flaw to circumvent expected security measures to perform actions which would otherwise be restricted.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2013-12-03 CVE Reserved
- 2014-03-31 CVE Published
- 2024-02-14 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/66596 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2014-0343.html | 2017-01-07 | |
http://rhn.redhat.com/errata/RHSA-2014-0344.html | 2017-01-07 | |
http://rhn.redhat.com/errata/RHSA-2014-0345.html | 2017-01-07 | |
http://secunia.com/advisories/57675 | 2017-01-07 | |
https://access.redhat.com/security/cve/CVE-2014-0093 | 2015-05-14 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1070046 | 2015-05-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 6.2.2 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "6.2.2" | - |
Affected
|