Логотип exploitDog
bind:CVE-2012-4549
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2012-4549

Количество 5

Количество 5

ubuntu логотип

CVE-2012-4549

около 13 лет назад

The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2012-4549

около 13 лет назад

The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2012-4549

около 13 лет назад

The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2012-4549

около 13 лет назад

The processInvocation function in org.jboss.as.ejb3.security.Authoriza ...

CVSS2: 5.8
EPSS: Низкий
github логотип

GHSA-4crg-m9w3-g9fc

больше 3 лет назад

The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2012-4549

The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.

CVSS2: 5.8
0%
Низкий
около 13 лет назад
redhat логотип
CVE-2012-4549

The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.

CVSS2: 5.8
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2012-4549

The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.

CVSS2: 5.8
0%
Низкий
около 13 лет назад
debian логотип
CVE-2012-4549

The processInvocation function in org.jboss.as.ejb3.security.Authoriza ...

CVSS2: 5.8
0%
Низкий
около 13 лет назад
github логотип
GHSA-4crg-m9w3-g9fc

The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу