CVE Vulnerabilities

CVE-2012-4549

Published: Jan 05, 2013 | Modified: Jan 15, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.

Affected Software

Name Vendor Start Version End Version
Jboss_enterprise_application_platform Redhat * 6.0.0 (including)
Jboss_enterprise_application_platform Redhat 4.2.0 (including) 4.2.0 (including)
Jboss_enterprise_application_platform Redhat 4.3.0 (including) 4.3.0 (including)
Jboss_enterprise_application_platform Redhat 5.0.0 (including) 5.0.0 (including)
Jboss_enterprise_application_platform Redhat 5.0.1 (including) 5.0.1 (including)
Jboss_enterprise_application_platform Redhat 5.1.0 (including) 5.1.0 (including)
Jboss_enterprise_application_platform Redhat 5.1.1 (including) 5.1.1 (including)
Jboss_enterprise_application_platform Redhat 5.1.2 (including) 5.1.2 (including)
Jboss_enterprise_application_platform Redhat 5.2.0 (including) 5.2.0 (including)
Jboss_enterprise_application_platform Redhat 5.2.1 (including) 5.2.1 (including)
Jboss_enterprise_application_platform Redhat 5.2.2 (including) 5.2.2 (including)

References