CVE Vulnerabilities

CVE-2012-1167

Published: Nov 23, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V2
4.6 MODERATE
AV:N/AC:H/Au:S/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.

Affected Software

NameVendorStart VersionEnd Version
Jboss_enterprise_application_platformRedhat5.1.0 (including)5.1.0 (including)
Jboss_enterprise_application_platformRedhat5.1.1 (including)5.1.1 (including)
JBEWP 5 for RHEL 5RedHatjbossas-web-0:5.1.2-10.ep5.el5*
JBEWP 5 for RHEL 5RedHatjboss-naming-0:5.0.3-4.CP01_patch_01.1.ep5.el5*
JBEWP 5 for RHEL 6RedHatjbossas-web-0:5.1.2-10.ep5.el6*
JBEWP 5 for RHEL 6RedHatjboss-naming-0:5.0.3-4.CP01_patch_01.2.ep5.el6*
JBoss Enterprise BRMS Platform 5.3RedHat*
Red Hat JBoss Enterprise Application Platform 5.1RedHat*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4RedHatjbossas-0:5.1.2-10.ep5.el4*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4RedHatjboss-naming-0:5.0.3-4.CP01_patch_01.1.ep5.el4*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5RedHatjbossas-0:5.1.2-10.ep5.el5*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5RedHatjboss-naming-0:5.0.3-4.CP01_patch_01.1.ep5.el5*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6RedHatjbossas-0:5.1.2-10.ep5.el6*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6RedHatjboss-naming-0:5.0.3-4.CP01_patch_01.2.ep5.el6*
Red Hat JBoss Portal 5.2RedHat*
Red Hat JBoss SOA Platform 5.3RedHat*
Red Hat JBoss Web Platform 5.1RedHat*

References