IssueDescription: It was found that Java Security Manager permissions configured via a policy file were not properly applied, causing all deployed applications to be granted the java.security.AllPermission permission. In certain cases, an attacker could use this flaw to circumvent expected security measures to perform actions which would otherwise be restricted.
Acknowledgements: This issue was discovered by Josef Cacek of the Red Hat JBoss EAP Quality Engineering team.
This issue has been addressed in following products: Red Hat JBoss Enterprise Application Platform 6.2.2 Via RHSA-2014:0345 https://rhn.redhat.com/errata/RHSA-2014-0345.html
This issue has been addressed in following products: JBEAP 6.2 for RHEL 5 JBEAP 6 for RHEL 5 Via RHSA-2014:0343 https://rhn.redhat.com/errata/RHSA-2014-0343.html
This issue has been addressed in following products: JBEAP 6.2 for RHEL 6 JBEAP 6 for RHEL 6 Via RHSA-2014:0344 https://rhn.redhat.com/errata/RHSA-2014-0344.html
This issue has been addressed in the following products: Red Hat JBoss BPM Suite 6.0.3 Via RHSA-2014:1291 https://rhn.redhat.com/errata/RHSA-2014-1291.html
This issue has been addressed in the following products: Red Hat JBoss BRMS 6.0.3 Via RHSA-2014:1290 https://rhn.redhat.com/errata/RHSA-2014-1290.html
This issue has been addressed in the following products: JBoss Fuse Service Works 6.0.0 Via RHSA-2014:1995 https://rhn.redhat.com/errata/RHSA-2014-1995.html
This issue has been addressed in the following products: JBoss Portal 6.2.0 Via RHSA-2015:1009 https://rhn.redhat.com/errata/RHSA-2015-1009.html