Description
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2013-1784.html
http://rhn.redhat.com/errata/RHSA-2013-1785.html
http://rhn.redhat.com/errata/RHSA-2013-1786.html
http://rhn.redhat.com/errata/RHSA-2015-0850.html
http://rhn.redhat.com/errata/RHSA-2015-0851.html
http://www.securitytracker.com/id/1029431
Related Vulnerabilities
CVE-2023-1584 Vulnerability in maven package io.quarkus:quarkus-oidc
CVE-2016-4434 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-ext-jdk14
CVE-2015-0250 Vulnerability in maven package org.apache.xmlgraphics:batik-dom
CVE-2020-2260 Vulnerability in maven package org.jenkins-ci.plugins:perfecto