An SQL injection vulnerability was found in dashbuilder.
Original Jira: https://issues.jboss.org/browse/DASHBUILDE-113
IssueDescription:
It was identified that PicketBox/JBossSX allowed any deployed application to alter or read the underlying application server configuration and state without any authorization checks. An attacker able to deploy applications could use this flaw to circumvent security constraints applied to other applications deployed on the same system, disclose privileged information, and in certain cases allow arbitrary code execution.