JBoss Enterprise Application Platform Multiple Vulnerbilities
Last Update Date:
5 Dec 2013 10:01
Release Date:
5 Dec 2013
3616
Views
RISK: Medium Risk
TYPE: Servers - Internet App Servers
Multiple vulnerabilities have been identified in JBoss Enterprise Application Platform. A remote authenticated user can bypass security controls. A local user can obtain elevated privileges on the target system.
- The HawtJNI Library class writes native libraries to a predictable file name in the '/tmp' directory in certain cases. A local user can overwrite the files before they are executed.
- A remote authenticated user can exploit a flaw in the EJB invocation handler implementation when performing method-level authorization for JAX-WS Service endpoints to invoke a JAX-WS handler that they are not authorized to invoke.
Impact
- Remote Code Execution
System / Technologies affected
- JBoss Enterprise Application Platform 6
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix.
Vulnerability Identifier
Source
Related Link
Share with