]
Brian Stansberry updated WFLY-4341:
-----------------------------------
Summary: CVE-2014-7853 JacORB Subsystem: Information disclosure via incorrect
sensitivity classification of attribute (was: CVE-2014-7853 JBoss AS/WildFly JacORB
Subsystem: Information disclosure via incorrect sensitivity classification of attribute)
CVE-2014-7853 JacORB Subsystem: Information disclosure via incorrect
sensitivity classification of attribute
------------------------------------------------------------------------------------------------------------
Key: WFLY-4341
URL:
https://issues.jboss.org/browse/WFLY-4341
Project: WildFly
Issue Type: Bug
Components: IIOP
Affects Versions: 8.0.0.Final, 8.1.0.Final, 8.2.0.Final, 9.0.0.Alpha1
Reporter: Brian Stansberry
Assignee: Brian Stansberry
Fix For: 9.0.0.Beta1
It was discovered that the JacORB subsystem incorrectly assigned socket-binding-ref
sensitivity classification for the security-domain attribute. An authenticated user with a
role that has access to attributes with socket-binding-ref and not security-domain-ref
sensitivity classification could use this flaw to access sensitive information present in
the security-domain attribute.