The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote attackers to bypass the WebRemote annotation restriction and obtain information about arbitrary classes and methods on the server classpath via unspecified vectors.
References
Link | Resource |
---|---|
http://rhn.redhat.com/errata/RHSA-2014-0045.html | Vendor Advisory |
http://secunia.com/advisories/56572 | Vendor Advisory |
http://www.securitytracker.com/id/1029652 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1044794 | Patch Vendor Advisory |
https://github.com/seam2/jboss-seam/commit/090aa6252affc978a96c388e3fc2c1c2688d9bb5 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2014-01-23T00:00:00
Updated: 2014-01-22T23:57:00
Reserved: 2013-11-04T00:00:00
Link: CVE-2013-6448
JSON object: View
NVD Information
Status : Analyzed
Published: 2014-01-23T00:55:03.380
Modified: 2014-01-23T18:17:27.057
Link: CVE-2013-6448
JSON object: View
Redhat Information
No data.
CWE