Multiple JBoss products contain a flaw that is triggered when WebPermissionMapping creates arbitrary permissions that are not properly checked by the program. This may allow an attacker to create a permission that would allow them to bypass restrictions.
Currently, there are no known workarounds or upgrades to correct this issue. However, Red Hat has released a patch to address this vulnerability. Check the Red Hat security advisory in the references section.