Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-4572

Опубликовано: 20 мая 2013
Источник: redhat
CVSS2: 3.7
EPSS Низкий

Описание

Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Portal 6SecurityAffected
Red Hat JBoss Enterprise Application Platform 6.1FixedRHSA-2013:083320.05.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-commons-daemon-eap6FixedRHSA-2013:083920.05.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-commons-daemon-jsvc-eap6FixedRHSA-2013:083920.05.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-commons-pool-eap6FixedRHSA-2013:083920.05.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-cxfFixedRHSA-2013:083920.05.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-cxf-xjc-utilsFixedRHSA-2013:083920.05.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5atinjectFixedRHSA-2013:083920.05.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5atinject-eap6FixedRHSA-2013:083920.05.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5codehaus-jacksonFixedRHSA-2013:083920.05.2013

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=872059JBoss: custom authorization module implementations shared between applications

EPSS

Процентиль: 18%
0.00058
Низкий

3.7 Low

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.

nvd
больше 12 лет назад

Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.

debian
больше 12 лет назад

Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and J ...

github
больше 3 лет назад

Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.

EPSS

Процентиль: 18%
0.00058
Низкий

3.7 Low

CVSS2

Уязвимость CVE-2012-4572