CVE-2013-2133
06.12.2013, 17:55
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | jboss_enterprise_application_platform | 𝑥 ≤ 6.1.0 |
redhat | jboss_enterprise_application_platform | 4.2.0 |
redhat | jboss_enterprise_application_platform | 4.2.0:cp09 |
redhat | jboss_enterprise_application_platform | 4.3.0 |
redhat | jboss_enterprise_application_platform | 4.3.0:cp10 |
redhat | jboss_enterprise_application_platform | 5.0.0 |
redhat | jboss_enterprise_application_platform | 5.0.1 |
redhat | jboss_enterprise_application_platform | 5.1.0 |
redhat | jboss_enterprise_application_platform | 5.1.1 |
redhat | jboss_enterprise_application_platform | 5.1.2 |
redhat | jboss_enterprise_application_platform | 5.2.0 |
redhat | jboss_enterprise_application_platform | 5.2.1 |
redhat | jboss_enterprise_application_platform | 5.2.2 |
redhat | jboss_enterprise_application_platform | 6.0.0 |
redhat | jboss_enterprise_application_platform | 6.0.1 |
redhat | enterprise_linux | 6.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
References