Description
The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspecified impact via unknown vectors.
Remediation
References
https://github.com/droolsjbpm/kie-wb-distributions/commit/90eed433d3
http://rhn.redhat.com/errata/RHSA-2015-0235.html
http://rhn.redhat.com/errata/RHSA-2015-0234.html
Related Vulnerabilities
CVE-2021-29484 Vulnerability in npm package ghost
CVE-2012-5633 Vulnerability in maven package org.apache.cxf:cxf-bundle-minimal
CVE-2014-3464 Vulnerability in maven package org.wildfly:wildfly-ejb3
CVE-2009-2901 Vulnerability in maven package tomcat:catalina
CVE-2023-49093 Vulnerability in maven package org.htmlunit:htmlunit