#VU83849 Improper access control in JBoss Enterprise Application Platform - CVE-2023-4503
Published: December 4, 2023
JBoss Enterprise Application Platform
Red Hat Inc.
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to custom provisioning of eap-galleon creates unsecured http-invoker, when using Galleon to provision custom EAP or EAP-XP servers. A remote attacker can bypass implemented security restrictions and access remote HTTP services available from the server.