The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspecified impact via unknown vectors.
References
Link | Resource |
---|---|
http://rhn.redhat.com/errata/RHSA-2015-0234.html | Vendor Advisory |
http://rhn.redhat.com/errata/RHSA-2015-0235.html | Vendor Advisory |
https://github.com/droolsjbpm/kie-wb-distributions/commit/90eed433d3 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2015-02-20T16:00:00
Updated: 2015-02-20T15:57:00
Reserved: 2014-10-10T00:00:00
Link: CVE-2014-8115
JSON object: View
NVD Information
Status : Analyzed
Published: 2015-02-20T16:59:03.290
Modified: 2015-03-23T16:53:32.317
Link: CVE-2014-8115
JSON object: View
Redhat Information
No data.
CWE