Jboss EAP Permissions Privileges and Access Controls Vulnerability - CVE-2014-3464 - Vulnerability Database

Jboss EAP Permissions Privileges and Access Controls Vulnerability - CVE-2014-3464

Medium
Reference: CVE-2014-3464
Title: Jboss EAP Permissions Privileges and Access Controls Vulnerability
Overview:

The EJB invocation handler implementation in Red Hat JBossWS as used in JBoss Enterprise Application Platform (EAP) 6.2.0 and 6.3.0 does not properly enforce the method level restrictions for outbound messages which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2133.