AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2013-2133

MEDIUM · CVSS 5.5 EPSS 1.81%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2013-12-06 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2013-2133
Severity
MEDIUM
CVSS
5.5
EPSS
1.81%

Original NVD Description

The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.