LiveActive security incident?Get immediate response
CVE Record

CVE-2014-0245: It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thre...

It was found that the implementation of the GTNSubjectCreatingInterceptor class in gatein-wsrp was not thread safe. For a specific WSRP endpoint, under high-concurrency scenarios or scenarios where SOAP messages take long to execute, it was possible for an unauthenticated remote attacker to gain privileged information if WS-Security is enabled for the WSRP Consumer, and the endpoint in question is being used by a privileged user. This affects JBoss Portal 6.2.0.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2014-0245 is an information exposure issue in Red Hat JBoss Portal 6.2.0. A threading flaw in gatein-wsrp could let an unauthenticated remote attacker see privileged information, but only under specific WSRP/SOAP conditions involving WS-Security and privileged endpoint use.

Executive priority

Treat as a targeted legacy-platform risk. Prioritize if JBoss Portal 6.2.0 is still running with WSRP and WS-Security enabled, especially on externally reachable systems. If the product is retired or not configured this way, urgency is lower.

Technical view

The vulnerable component is gatein-wsrp's GTNSubjectCreatingInterceptor. Its implementation was not thread safe, creating a race condition for a specific WSRP endpoint during high concurrency or long-running SOAP processing. Exposure requires WS-Security enabled for the WSRP Consumer and use of the endpoint by a privileged user.

Likely exposure

Exposure appears narrow: JBoss Portal 6.2.0 deployments using the affected WSRP endpoint with WS-Security enabled for the WSRP Consumer. Systems without that product, version, endpoint usage, or configuration are not shown as affected by the supplied sources.

Exploitation context

The source bundle does not show active exploitation, public exploit availability, or CISA KEV listing. The described attack is remote and unauthenticated, but depends on timing, concurrency, SOAP execution duration, WS-Security configuration, and privileged-user activity.

Researcher notes

The key evidence is the non-thread-safe GTNSubjectCreatingInterceptor behavior. The vulnerability is conditional and configuration-dependent. The supplied sources do not provide CVSS, CWE, exploit telemetry, or detailed patch mechanics beyond Red Hat references and RHSA-2015:1009.

Mitigation direction

  • Identify any JBoss Portal 6.2.0 deployments.
  • Review Red Hat RHSA-2015:1009 and apply vendor-supported updates.
  • Check Red Hat CVE guidance for affected packages and remediation details.
  • Reduce exposure of WSRP endpoints where business use allows.
  • Limit privileged use of affected endpoints until remediated.

Validation and detection

  • Inventory JBoss Portal versions and confirm whether 6.2.0 is present.
  • Determine whether gatein-wsrp and WSRP endpoints are enabled.
  • Verify WS-Security configuration for WSRP Consumer usage.
  • Check whether privileged users use the affected endpoint.
  • Confirm remediation status against Red Hat advisory RHSA-2015:1009.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2014-0245 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
4Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Red HatJBoss Portal6.2.0Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.