5.5
CVE-2013-2133
- EPSS 1.81%
- Veröffentlicht 06.12.2013 17:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Erkennungen
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Jboss Enterprise Application Platform Version <= 6.1.0
Redhat ≫ Jboss Enterprise Application Platform Version 4.2.0
Redhat ≫ Jboss Enterprise Application Platform Version 4.2.0 Update cp09
Redhat ≫ Jboss Enterprise Application Platform Version 4.3.0
Redhat ≫ Jboss Enterprise Application Platform Version 4.3.0 Update cp10
Redhat ≫ Jboss Enterprise Application Platform Version 5.0.0
Redhat ≫ Jboss Enterprise Application Platform Version 5.0.1
Redhat ≫ Jboss Enterprise Application Platform Version 5.1.0
Redhat ≫ Jboss Enterprise Application Platform Version 5.1.1
Redhat ≫ Jboss Enterprise Application Platform Version 5.1.2
Redhat ≫ Jboss Enterprise Application Platform Version 5.2.0
Redhat ≫ Jboss Enterprise Application Platform Version 5.2.1
Redhat ≫ Jboss Enterprise Application Platform Version 5.2.2
Redhat ≫ Jboss Enterprise Application Platform Version 6.0.0
Redhat ≫ Jboss Enterprise Application Platform Version 6.0.1
Redhat ≫ Enterprise Linux Version 5
Redhat ≫ Enterprise Linux Version 6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.81% | 0.758 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 8 | 4.9 |
AV:N/AC:L/Au:S/C:P/I:P/A:N
|
http://rhn.redhat.com/errata/RHSA-2013-1784.html
http://rhn.redhat.com/errata/RHSA-2013-1785.html
http://rhn.redhat.com/errata/RHSA-2013-1786.html
http://www.securitytracker.com/id/1029431
http://rhn.redhat.com/errata/RHSA-2015-0850.html
http://rhn.redhat.com/errata/RHSA-2015-0851.html