Vulnerability Description
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be granted the java.security.AllPermission permission and allows remote attackers to bypass intended access restrictions.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Enterprise Application Platform | 6.2.2 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2014-0343.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0344.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0345.htmlVendor Advisory
- http://secunia.com/advisories/57675Vendor Advisory
- http://www.securityfocus.com/bid/66596
- http://rhn.redhat.com/errata/RHSA-2014-0343.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0344.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0345.htmlVendor Advisory
- http://secunia.com/advisories/57675Vendor Advisory
- http://www.securityfocus.com/bid/66596
FAQ
What is CVE-2014-0093?
CVE-2014-0093 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.2, when using a Java Security Manager (JSM), does not properly apply permissions defined by a policy file, which causes applications to be gra...
How severe is CVE-2014-0093?
CVE-2014-0093 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0093?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Jboss Enterprise Application Platform.