VDB

RHSA-2014%3A1288

RHSA-2014%3A1288 PUBLISHED CVSS 3.299999952316284 LOW

It was discovered that the implementation of org.hibernate.validator.util.ReflectionHelper together with the permissions required to run Hibernate Validator under the Java Security Manager could allow a malicious application deployed in the same application container to execute several actions with escalated privileges, which might otherwise not be possible. This flaw could be used to perform various attacks, including but not restricted to, arbitrary code execution in systems that are otherwise secured by the Java Security Manager.

Risk Scores

CVSS 2.0
3.299999952316284

Affected Products

VendorProductVersions
Red HatRed Hat JBoss Enterprise Application Platform 6.3

Timeline

  • Sep 23, 2014 CVE Published
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Distribution Patch
  • Apr 29, 2026 Security Advisory
  • Apr 29, 2026 Security Advisory
  • May 14, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›