Release date:
Updated on:
Affected Systems:
RedHat Linux <6.2.0
Description:
--------------------------------------------------------------------------------
Bugtraq id: 64125
CVE (CAN) ID: CVE-2013-2133
JBoss Enterprise Application Platform (EAP) is a middleware Platform for J2EE applications.
In versions earlier than JBoss Enterprise Application Platform 6.2.0, Red Hat JBossWS does not properly implement method-level restrictions on JAS-WS service endpoints, and security vulnerabilities exist in EJB call handler implementation, allows authenticated remote users to access restricted JAS-WS handlers illegally.
<* Source: Richard Opalka
Arun Neelicattu
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
RedHat
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.redhat.com/apps/support/errata/index.html