| Vulnerability Name: | CVE-2012-4550 (CCN-81002) | ||||||||||||
| Assigned: | 2012-12-19 | ||||||||||||
| Published: | 2012-12-19 | ||||||||||||
| Updated: | 2013-05-07 | ||||||||||||
| Summary: | JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, when using role-based authorization for Enterprise Java Beans (EJB) access, does not call the intended authorization modules, which prevents JACC permissions from being applied and allows remote attackers to obtain access to the EJB. Per https://bugzilla.redhat.com/show_bug.cgi?id=870871#c7 "This issue did not affect JBoss Enterprise Application Platform versions 4.x and 5.x." | ||||||||||||
| CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||||||
| CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
4.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2012-4550 Source: CCN Type: RHSA-2012-1591 Important: JBoss Enterprise Application Platform 6.0.1 update Source: REDHAT Type: Vendor Advisory RHSA-2012:1591 Source: CCN Type: RHSA-2012-1592 Important: JBoss Enterprise Application Platform 6.0.1 update Source: REDHAT Type: Vendor Advisory RHSA-2012:1592 Source: CCN Type: RHSA-2012-1594 Important: JBoss Enterprise Application Platform 6.0.1 update Source: REDHAT Type: Vendor Advisory RHSA-2012:1594 Source: SECUNIA Type: Vendor Advisory 51607 Source: CCN Type: JBoss Web site JBoss Enterprise Application Platform Source: XF Type: UNKNOWN jbeap-modules-security-bypass(81002) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||