It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, under high-concurrency scenarios or scenarios where SOAP messages take long to execute, it was possible for an unauthenticated remote attacker to gain privileged information if WS-Security is enabled for the WSRP Consumer, and the endpoint in question is being used by a privileged user. This affects JBoss Portal 6.2.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2014-0283 It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, under high-concurrency scenarios or scenarios where SOAP messages take long to execute, it was possible for an unauthenticated remote attacker to gain privileged information if WS-Security is enabled for the WSRP Consumer, and the endpoint in question is being used by a privileged user. This affects JBoss Portal 6.2.0.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T09:05:39.384Z

Reserved: 2013-12-03T00:00:00

Link: CVE-2014-0245

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-01-02T20:15:17.770

Modified: 2024-11-21T02:01:44.717

Link: CVE-2014-0245

cve-icon Redhat

Severity : Low

Publid Date: 2015-03-10T00:00:00Z

Links: CVE-2014-0245 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses