Description
Red Hat JBoss Enterprise Application Platform (JBEAP) 6.2.0 and JBoss WildFly Application Server, when run under a security manager, do not properly restrict access to the Modular Service Container (MSC) service registry, which allows local users to modify the server via a crafted deployment.
Remediation
References
Related Vulnerabilities
concrete5 Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-8082)
OpenSSL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-3195)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2017-5659)
WordPress Plugin Blogroll Fun-Show Last Post and Last Update Time Cross-Site Scripting (0.8.4)