First published: Tue Jan 14 2014(Updated: )
IssueDescription: In Red Hat JBoss Enterprise Application Platform, when running under a security manager, it was possible for deployed code to get access to the Modular Service Container (MSC) service registry without any permission checks. This could allow malicious deployments to modify the internal state of the server in various ways.
Affected Software | Affected Version | How to fix |
---|---|---|
JBoss Enterprise Application Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1052783 is considered critical due to the potential for unauthorized access to the Modular Service Container.
To fix REDHAT-BUG-1052783, ensure to apply the latest patches provided by Red Hat for JBoss Enterprise Application Platform.
REDHAT-BUG-1052783 affects multiple versions of Red Hat JBoss Enterprise Application Platform that run under a security manager.
The risks associated with REDHAT-BUG-1052783 include potential modification of the service registry by malicious code, leading to service disruptions or security breaches.
Currently, the best practice is to apply security updates rather than relying on workarounds for REDHAT-BUG-1052783.