CVE Vulnerabilities

CVE-2012-2148

Improper Privilege Management

Published: Dec 06, 2019 | Modified: Nov 21, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Jboss_community_application_serverRedhat7.1.1 (including)7.1.1 (including)

Potential Mitigations

References