CVE-2015-5304

Impact:
Moderate
Public Date:
2015-12-02
CWE:
CWE-862
Bugzilla:
1273046: CVE-2015-5304 JBoss EAP: missing authorization check for Monitor/Deployer/Auditor role when shutting down server
It was found that JBoss EAP did not properly authorize a user performing a shut down. A remote user with the Monitor, Deployer, or Auditor role could use this flaw to shut down the EAP server, which is an action restricted to admin users.

Find out more about CVE-2015-5304 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4
Base Metrics AV:N/AC:L/Au:S/C:N/I:N/A:P
Access Vector Network
Access Complexity Low
Authentication Single
Confidentiality Impact None
Integrity Impact None
Availability Impact Partial

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 6.4 RHSA-2015:2541 2015-12-02
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server (jboss-ec2-eap) RHSA-2015:2542 2015-12-02
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server RHSA-2015:2539 2015-12-02
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 Server RHSA-2015:2538 2015-12-02
Red Hat JBoss Enterprise Application Platform 6.3 for RHEL 7 Server RHSA-2015:2540 2015-12-02

Acknowledgements

This issue was discovered by Ladislav Thon of Red Hat Middleware Quality Engineering.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.