]
Brian Stansberry updated WFLY-4341:
-----------------------------------
Security: (was: Red Hat Internal)
CVE-2014-7853 JBoss AS/WildFly JacORB Subsystem: Information
disclosure via incorrect sensitivity classification of attribute
-----------------------------------------------------------------------------------------------------------------------------
Key: WFLY-4341
URL:
https://issues.jboss.org/browse/WFLY-4341
Project: WildFly
Issue Type: Bug
Components: IIOP
Affects Versions: 8.0.0.Final, 8.1.0.Final, 8.2.0.Final, 9.0.0.Alpha1
Reporter: Brian Stansberry
Assignee: Brian Stansberry
Fix For: 9.0.0.Beta1
It was discovered that the JacORB subsystem incorrectly assigned socket-binding-ref
sensitivity classification for the security-domain attribute. An authenticated user with a
role that has access to attributes with socket-binding-ref and not security-domain-ref
sensitivity classification could use this flaw to access sensitive information present in
the security-domain attribute.