First published: Tue Nov 18 2014(Updated: )
It was discovered that the Role Based Access Control (RBAC) implementation did not sufficiently verify all authorization conditions required by the Maintainer role to perform certain administrative actions. An authenticated user with the Maintainer role can use this flaw to add, modify or undefine a limited set of attributes and their values which otherwise cannot be written to.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Enterprise Application Platform | =6.2.0 | |
Redhat Jboss Enterprise Application Platform | =6.2.1 | |
Redhat Jboss Enterprise Application Platform | =6.2.2 | |
Redhat Jboss Enterprise Application Platform | =6.2.3 | |
Redhat Jboss Enterprise Application Platform | =6.2.4 | |
Redhat Jboss Enterprise Application Platform | =6.3.0 | |
Redhat Jboss Enterprise Application Platform | =6.3.1 | |
Redhat Jboss Enterprise Application Platform | =6.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.