Description
The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspecified impact via unknown vectors.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2015-0234.html
http://rhn.redhat.com/errata/RHSA-2015-0235.html
https://github.com/droolsjbpm/kie-wb-distributions/commit/90eed433d3
Related Vulnerabilities
CVE-2022-29045 Vulnerability in maven package org.jenkins-ci.plugins:promoted-builds
CVE-2015-0201 Vulnerability in maven package org.springframework:spring-websocket
CVE-2019-10201 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2016-3092 Vulnerability in maven package commons-fileupload:commons-fileupload
CVE-2017-12632 Vulnerability in maven package org.apache.nifi:nifi