Thread Safety Issue in JBoss Portal by Red Hat
CVE-2014-0245
5.9MEDIUM
What is CVE-2014-0245?
A thread safety vulnerability exists in the GTNSubjectCreatingInterceptor class of the GateIn WSRP implementation within JBoss Portal 6.2.0. Under high concurrency scenarios or notably long SOAP message executions, an unauthenticated remote attacker could exploit this vulnerability to access privileged information. This is particularly concerning if WS-Security is enabled for the WSRP Consumer and the endpoint is accessed by a privileged user, creating a potential attack vector that compromises data integrity and confidentiality.
Affected Version(s)
JBoss Portal 6.2.0