CVE Vulnerabilities

CVE-2012-2148

Improper Privilege Management

Published: Dec 06, 2019 | Modified: Dec 16, 2019
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

An issue exists in the property replacements feature in any descriptor in JBoxx AS 7.1.1 ignores java security policies

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Jboss_community_application_server Redhat 7.1.1 (including) 7.1.1 (including)

Potential Mitigations

References