Description
The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspecified impact via unknown vectors.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2015-0234.html
http://rhn.redhat.com/errata/RHSA-2015-0235.html
https://github.com/droolsjbpm/kie-wb-distributions/commit/90eed433d3
Related Vulnerabilities
CVE-2023-23638 Vulnerability in maven package org.apache.dubbo:dubbo-common
CVE-2020-25640 Vulnerability in maven package org.jboss.genericjms:generic-jms-ra-jar
CVE-2022-23106 Vulnerability in maven package io.jenkins:configuration-as-code
CVE-2023-37956 Vulnerability in maven package org.jenkins-ci.plugins:test-results-aggregator
CVE-2016-8608 Vulnerability in maven package org.jbpm:jbpm-designer-client