CVE Vulnerabilities

CVE-2012-4549

Published: Jan 05, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.

Affected Software

NameVendorStart VersionEnd Version
Jboss_enterprise_application_platformRedhat*6.0.0 (including)
Jboss_enterprise_application_platformRedhat4.2.0 (including)4.2.0 (including)
Jboss_enterprise_application_platformRedhat4.3.0 (including)4.3.0 (including)
Jboss_enterprise_application_platformRedhat5.0.0 (including)5.0.0 (including)
Jboss_enterprise_application_platformRedhat5.0.1 (including)5.0.1 (including)
Jboss_enterprise_application_platformRedhat5.1.0 (including)5.1.0 (including)
Jboss_enterprise_application_platformRedhat5.1.1 (including)5.1.1 (including)
Jboss_enterprise_application_platformRedhat5.1.2 (including)5.1.2 (including)
Jboss_enterprise_application_platformRedhat5.2.0 (including)5.2.0 (including)
Jboss_enterprise_application_platformRedhat5.2.1 (including)5.2.1 (including)
Jboss_enterprise_application_platformRedhat5.2.2 (including)5.2.2 (including)
Jbossas4Ubuntuhardy*
Jbossas4Ubuntulucid*
Jbossas4Ubuntuoneiric*
Jbossas4Ubuntuprecise*
Jbossas4Ubuntuquantal*
Jbossas4Ubunturaring*
Jbossas4Ubuntusaucy*
Jbossas4Ubuntuutopic*

References