Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote authenticated users when deleting a plug-in configuration update from the group connection properties history, which prevents such activities from being recorded in the audit trail.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2014-04-01T01:00:00

Updated: 2014-04-01T00:57:00

Reserved: 2011-11-29T00:00:00


Link: CVE-2011-4573

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-04-01T06:35:52.497

Modified: 2014-04-01T14:38:49.943


Link: CVE-2011-4573

JSON object: View

cve-icon Redhat Information

No data.

CWE