The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote attackers to bypass the WebRemote annotation restriction and obtain information about arbitrary classes and methods on the server classpath via unspecified vectors.
                
            References
                    | Link | Resource | 
|---|---|
| http://www.securitytracker.com/id/1029652 | |
| https://github.com/seam2/jboss-seam/commit/090aa6252affc978a96c388e3fc2c1c2688d9bb5 | |
| http://rhn.redhat.com/errata/RHSA-2014-0045.html | Vendor Advisory | 
| http://secunia.com/advisories/56572 | Vendor Advisory | 
| https://bugzilla.redhat.com/show_bug.cgi?id=1044794 | Patch Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
Information
                Published : 2014-01-22 16:55
Updated : 2014-01-23 10:17
NVD link : CVE-2013-6448
Mitre link : CVE-2013-6448
JSON object : View
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
Products Affected
                redhat
- jboss_seam_2_framework


