Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-5626

Опубликовано: 06 фев. 2015
Источник: redhat
CVSS2: 2.6

Описание

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.

Отчет

Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 4 and 5; Red Hat JBoss Enterprise Portal Platform 5; Red Hat JBoss Enterprise SOA Platform 4 and 5; and Red Hat JBoss Enterprise Web Platform 5 are now in Phase 3, Extended Life Support, of their respective life cycles. This issue has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat JBoss Middleware and Red Hat JBoss Operations Network Product Update and Support Policy: https://access.redhat.com/support/policy/updates/jboss_notes/

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5jbosssxWill not fix
Red Hat JBoss Enterprise Application Platform 5jbosssxWill not fix
Red Hat JBoss Enterprise Application Platform 6picketlinkNot affected
Red Hat JBoss Enterprise Web Server 1eap_ewp-4.xWill not fix
Red Hat JBoss Enterprise Web Server 1ewp-5Will not fix
Red Hat JBoss Operations Network 3.1jbosssxNot affected
Red Hat JBoss Portal 4jbosssxWill not fix
Red Hat JBoss Portal 5jbosssxWill not fix
Red Hat JBoss SOA Platform 4.2jbosssxWill not fix
Red Hat JBoss SOA Platform 4.3jbosssxWill not fix

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=884426JBoss - EJB method invocation ignores roles specified using the @RunAs annotation

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.

CVSS3: 7.5
nvd
около 6 лет назад

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.

CVSS3: 7.5
debian
около 6 лет назад

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Applicati ...

github
почти 4 года назад

EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.

2.6 Low

CVSS2