Skip to main content

JBoss Enterprise Application Platform Multiple Vulnerbilities

Last Update Date: 5 Dec 2013 10:01 Release Date: 5 Dec 2013 3076 Views

RISK: Medium Risk

TYPE: Servers - Internet App Servers

TYPE: Internet App Servers

Multiple vulnerabilities have been identified in JBoss Enterprise Application Platform. A remote authenticated user can bypass security controls. A local user can obtain elevated privileges on the target system.

  1. The HawtJNI Library class writes native libraries to a predictable file name in the '/tmp' directory in certain cases. A local user can overwrite the files before they are executed.
  2. A remote authenticated user can exploit a flaw in the EJB invocation handler implementation when performing method-level authorization for JAX-WS Service endpoints to invoke a JAX-WS handler that they are not authorized to invoke.

Impact

  • Remote Code Execution

System / Technologies affected

  • JBoss Enterprise Application Platform 6

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix.

Vulnerability Identifier


Source


Related Link