CVE-2014-0248
Description
org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2014-0794.html
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2014-0793.html
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2014-0792.html
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2014-0791.html
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2014-0785.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | 5.2.0 | |
| redhat | jboss_enterprise_web_platform | 5.2.0 | |
| redhat | jboss_web_framework_kit | 2.5.0 | |
References
- http://rhn.redhat.com/errata/RHSA-2014-0785.html
- http://rhn.redhat.com/errata/RHSA-2014-0791.html
- http://rhn.redhat.com/errata/RHSA-2014-0792.html
- http://rhn.redhat.com/errata/RHSA-2014-0793.html
- http://rhn.redhat.com/errata/RHSA-2014-0794.html
- http://rhn.redhat.com/errata/RHSA-2015-1888.html
- http://secunia.com/advisories/59346
- http://secunia.com/advisories/59554
- http://secunia.com/advisories/59555
- http://www.securitytracker.com/id/1030457
- http://rhn.redhat.com/errata/RHSA-2014-0785.html
- http://rhn.redhat.com/errata/RHSA-2014-0791.html
- http://rhn.redhat.com/errata/RHSA-2014-0792.html
- http://rhn.redhat.com/errata/RHSA-2014-0793.html
- http://rhn.redhat.com/errata/RHSA-2014-0794.html
- http://rhn.redhat.com/errata/RHSA-2015-1888.html
- http://secunia.com/advisories/59346
- http://secunia.com/advisories/59554
- http://secunia.com/advisories/59555
- http://www.securitytracker.com/id/1030457
CWEs
CWE-94
Verify integrity in audit chain (admin only). AS-IS.