Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-1167

Опубликовано: 12 июн. 2012
Источник: redhat
CVSS2: 4.6
EPSS Низкий

Описание

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5SecurityAffected
Red Hat JBoss Portal 5RequirementsAffected
Red Hat JBoss SOA Platform 5SecurityAffected
JBEWP 5 for RHEL 5jbossas-webFixedRHSA-2012:102720.06.2012
JBEWP 5 for RHEL 5jboss-namingFixedRHSA-2012:102720.06.2012
JBEWP 5 for RHEL 6jbossas-webFixedRHSA-2012:102720.06.2012
JBEWP 5 for RHEL 6jboss-namingFixedRHSA-2012:102720.06.2012
JBoss Enterprise BRMS Platform 5.3FixedRHSA-2012:102822.06.2012
Red Hat JBoss Enterprise Application Platform 5.1FixedRHSA-2012:101319.06.2012
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4jbossasFixedRHSA-2012:102620.06.2012

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=802622JBoss: authentication bypass when running under JACC with ignoreBaseDecision on JBossWebRealm

EPSS

Процентиль: 74%
0.00815
Низкий

4.6 Medium

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.

nvd
около 13 лет назад

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.

debian
около 13 лет назад

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before ...

github
больше 3 лет назад

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.

EPSS

Процентиль: 74%
0.00815
Низкий

4.6 Medium

CVSS2