VDB
RHSA-2014%3A1288
RHSA-2014%3A1288
PUBLISHED
CVSS 3.299999952316284 LOW
It was discovered that the implementation of org.hibernate.validator.util.ReflectionHelper together with the permissions required to run Hibernate Validator under the Java Security Manager could allow a malicious application deployed in the same application container to execute several actions with escalated privileges, which might otherwise not be possible. This flaw could be used to perform various attacks, including but not restricted to, arbitrary code execution in systems that are otherwise secured by the Java Security Manager.
Risk Scores
CVSS 2.0
3.299999952316284
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 6.3 |
Timeline
- Sep 23, 2014 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2014:1288 advisory
- https://access.redhat.com/security/updates/classification/#low advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=appplatform&downloadType=distributions&version=6.3 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1120495 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2014/rhsa-2014_1288.json advisory
- https://access.redhat.com/security/cve/CVE-2014-3558 advisory
- https://www.cve.org/CVERecord?id=CVE-2014-3558 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-3558 advisory