The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous users password to be used.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jboss_enterprise_web_platform | Redhat | 5.2.0 | 5.2.0 |