Описание
The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated users to bypass intended role restrictions and perform arbitrary JMX operations via unspecified vectors.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss BRMS 5 | jbossas | Affected | ||
| Red Hat JBoss Portal 5 | jbossas | Will not fix | ||
| Red Hat JBoss SOA Platform 5 | jbossas | Affected | ||
| JBEWP 5 for RHEL 5 | aopalliance | Fixed | RHSA-2013:0196 | 24.01.2013 |
| JBEWP 5 for RHEL 5 | apache-cxf | Fixed | RHSA-2013:0196 | 24.01.2013 |
| JBEWP 5 for RHEL 5 | bsh2 | Fixed | RHSA-2013:0196 | 24.01.2013 |
| JBEWP 5 for RHEL 5 | glassfish-jaxb | Fixed | RHSA-2013:0196 | 24.01.2013 |
| JBEWP 5 for RHEL 5 | google-guice | Fixed | RHSA-2013:0196 | 24.01.2013 |
| JBEWP 5 for RHEL 5 | hibernate3 | Fixed | RHSA-2013:0196 | 24.01.2013 |
| JBEWP 5 for RHEL 5 | hibernate3-annotations | Fixed | RHSA-2013:0196 | 24.01.2013 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.9 Medium
CVSS2
Связанные уязвимости
The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated users to bypass intended role restrictions and perform arbitrary JMX operations via unspecified vectors.
The AuthorizationInterceptor in JBoss Enterprise Application Platform ...
The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated users to bypass intended role restrictions and perform arbitrary JMX operations via unspecified vectors.
EPSS
4.9 Medium
CVSS2