Description
The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspecified impact via unknown vectors.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2015-0234.html
http://rhn.redhat.com/errata/RHSA-2015-0235.html
https://github.com/droolsjbpm/kie-wb-distributions/commit/90eed433d3
Related Vulnerabilities
CVE-2022-28731 Vulnerability in maven package org.apache.jspwiki:jspwiki-war
CVE-2022-43766 Vulnerability in maven package org.apache.iotdb:iotdb-server
CVE-2014-0074 Vulnerability in maven package org.apache.shiro:shiro-core
CVE-2018-20677 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap-sass
CVE-2022-36885 Vulnerability in maven package com.coravy.hudson.plugins.github:github