Description
Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.
Remediation
References
Related Vulnerabilities
MySQL CVE-2014-4207 Vulnerability (CVE-2014-4207)
WordPress Plugin ThemeGrill Demo Importer Cross-Site Request Forgery (1.6.2)
WordPress Plugin Web Directory Free SQL Injection (1.6.9)
WordPress Plugin XEN Carousel Multiple Cross-Site Scripting Vulnerabilities (0.12.2)
Oracle Application Server Other Vulnerability (CVE-2006-5361)