SB2019100724 - Improper authorization in wildfly-security-manager in Red Hat JBoss Enterprise Application Platform
Published: October 7, 2019 Updated: November 27, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Authorization (CVE-ID: CVE-2019-14843)
The vulnerability allows an attacker to gain access to sensitive information.
The vulnerability exists due to improper authorization checks in WidlFly security manager, when running under JDK 11 or 8, that successfully authorizes requests for any requesters . A locally deployed application on the server can gain access to sensitive information.
Remediation
Install update from vendor's website.