Description
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.
Remediation
References
Related Vulnerabilities
WordPress Plugin WooCommerce SQL Injection (5.5.0)
Ruby Improper Input Validation Vulnerability (CVE-2018-8779)
WordPress Plugin VO Store Locator-WP Store Locator Unspecified Vulnerability (3.2.14)
MySQL CVE-2019-2580 Vulnerability (CVE-2019-2580)
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-29203)