CVE-2007-1354: Race Condition
The Access Control functionality (JMXOpsAccessControlFilter) in JMX Console in JBoss Application Server 4.0.2 and 4.0.5 before 20070416 uses a member variable to store the roles of the current user, which allows remote authenticated administrators to trigger a race condition and gain privileges by logging in during a session by a more privileged administrator, as demonstrated by privilege escalation from Read Mode to Write Mode.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-1354?
CVE-2007-1354 is considered to have a high severity due to its potential for privilege escalation.
How do I fix CVE-2007-1354?
Ensure you have applied any security patches released by JBoss for affected versions.
Which versions of JBoss Application Server are affected by CVE-2007-1354?
CVE-2007-1354 affects JBoss Application Server versions 4.0.2 and 4.0.5 prior to the 20070416 update.
Can CVE-2007-1354 be exploited remotely?
Yes, CVE-2007-1354 can be exploited remotely by authenticated administrators due to the nature of the race condition.
What impact does CVE-2007-1354 have on the system?
CVE-2007-1354 allows an attacker to gain elevated privileges, potentially compromising the security of the application.