Description
The default authorization constrains in KIE Workbench 6.0.x allows remote authenticated users to read or write to arbitrary files, bypass intended access restrictions, and possibly have other unspecified impact via unknown vectors.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2015-0234.html
http://rhn.redhat.com/errata/RHSA-2015-0235.html
https://github.com/droolsjbpm/kie-wb-distributions/commit/90eed433d3
Related Vulnerabilities
CVE-2012-6662 Vulnerability in maven package org.webjars:jquery-ui
CVE-2020-16023 Vulnerability in npm package electron
CVE-2018-1999040 Vulnerability in maven package org.csanchez.jenkins.plugins:kubernetes
CVE-2017-5656 Vulnerability in maven package org.apache.cxf:cxf-rt-ws-security
CVE-2016-4974 Vulnerability in maven package org.apache.qpid:qpid-jms-client