It was discovered that the JBoss Application Server (WildFly) JacORB subsystem incorrectly assigned socket-binding-ref sensitivity classification for the security-domain attribute. This flaw can be used by an authenticated user with a role that have access to attributes with socket-binding-ref and not security-domain-ref sensitivity classification to access sensitive information present in the security-domain attribute.
Acknowledgements: This issue was discovered by Darran Lofthouse of the Red Hat JBoss Enterprise Application Platform Team.
This issue has been addressed in the following products: JBoss Enterprise Application Platform 6.3.3 Via RHSA-2015:0215 https://rhn.redhat.com/errata/RHSA-2015-0215.html
This issue has been addressed in the following products: JBEAP 6.3.z for RHEL 6 Via RHSA-2015:0217 https://rhn.redhat.com/errata/RHSA-2015-0217.html
This issue has been addressed in the following products: JBEAP 6.3.z for RHEL 5 Via RHSA-2015:0216 https://rhn.redhat.com/errata/RHSA-2015-0216.html
This issue has been addressed in the following products: JBEAP 6.3.z for RHEL 7 Via RHSA-2015:0218 https://rhn.redhat.com/errata/RHSA-2015-0218.html
This issue has been addressed in the following products: Red Hat JBoss Operations Network 3.3 Via RHSA-2015:0920 https://rhn.redhat.com/errata/RHSA-2015-0920.html