5.5
CVSSv2

CVE-2013-2133

Published: 06/12/2013 Updated: 22/04/2019
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) prior to 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform 5.2.0

redhat jboss enterprise application platform 5.1.2

redhat jboss enterprise application platform 4.2.0

redhat jboss enterprise application platform 6.0.1

redhat jboss enterprise application platform 6.0.0

redhat jboss enterprise application platform 5.0.1

redhat jboss enterprise application platform 5.0.0

redhat jboss enterprise application platform

redhat jboss enterprise application platform 5.1.1

redhat jboss enterprise application platform 5.1.0

redhat jboss enterprise application platform 5.2.2

redhat jboss enterprise application platform 5.2.1

redhat jboss enterprise application platform 4.3.0

redhat enterprise linux 5

redhat enterprise linux 6.0

Vendor Advisories

Synopsis Low: Red Hat JBoss Enterprise Application Platform 620 update Type/Severity Security Advisory: Low Topic Updated Red Hat JBoss Enterprise Application Platform 620 packages thatfix two security issues, several bugs, and add various enhancements are nowavailable for Red Hat Enterprise Linux 5The ...
Synopsis Low: Red Hat JBoss Enterprise Application Platform 620 update Type/Severity Security Advisory: Low Topic Updated Red Hat JBoss Enterprise Application Platform 620 packages thatfix two security issues, several bugs, and add various enhancements are nowavailable for Red Hat Enterprise Linux 6The ...
A flaw was found in the way method-level authorization for JAX-WS Service endpoints was performed by the EJB invocation handler implementation Any restrictions declared on EJB methods were ignored when executing the JAX-WS handlers, and only class-level restrictions were applied A remote attacker who is authorized to access the EJB class, could i ...