CVE-2014-7849 PUBLISHED CVSS 4 MEDIUM

The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.

EPSS 0.40% · 60.5th percentile

Risk Scores

CVSS v2.0
4
EPSS Score
0.40%
60.5th percentile

Affected Products

VendorProductVersions
redhatjboss_enterprise_application_platform6.3.2, 6.2.0, 6.2.1
n/an/an/a

Timeline

References

Open in Interactive Console →