CVE-2014-7853

Impact:
Moderate
Public Date:
2015-02-11
CWE:
CWE-284->CWE-200
Bugzilla:
1165522: CVE-2014-7853 JBoss AS/WildFly JacORB Subsystem: Information disclosure via incorrect sensitivity classification of attribute
It was discovered that the JBoss Application Server (WildFly) JacORB subsystem incorrectly assigned socket-binding-ref sensitivity classification for the security-domain attribute. An authenticated user with a role that has access to attributes with socket-binding-ref and not security-domain-ref sensitivity classification could use this flaw to access sensitive information present in the security-domain attribute.

Find out more about CVE-2014-7853 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4.9
Base Metrics AV:N/AC:M/Au:S/C:P/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication Single
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 Server RHSA-2015:0218 2015-02-11
Red Hat JBoss Operations Network 3.3 RHSA-2015:0920 2015-04-30
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 Server RHSA-2015:0216 2015-02-11
Red Hat JBoss Enterprise Application Platform 6.3 RHSA-2015:0215 2015-02-11
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server RHSA-2015:0217 2015-02-11

Affected Packages State

Platform Package State
Red Hat JBoss Portal Platform 6 jacorb Will not fix
Red Hat JBoss EAP 5 Security Not affected
Red Hat JBoss Data Grid 6 jacorb Will not fix

Acknowledgements

This issue was discovered by Darran Lofthouse of the Red Hat JBoss Enterprise Application Platform Team.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.