CVE-2014-7849: Red Hat JBoss Enterprise Application Platform

Medium severity, CVSS 4.0. EPSS: 1.3% chance of exploitation in the next 30 days.

The Role Based Access Control (RBAC) implementation in JBoss Enterprise Application Platform (EAP) 6.2.0 through 6.3.2 does not properly verify authorization conditions, which allows remote authenticated users to add, modify, and undefine otherwise restricted attributes by leveraging the Maintainer role.

Affected products

  • Red Hat JBoss Enterprise Application Platform: version 6.2.0 only; version 6.2.1 only; version 6.2.2 only; version 6.2.3 only; version 6.2.4 only; version 6.3.0 only; …

Published 2015-02-13. Last modified 2026-06-17.