4.6
CVE-2012-1167
- EPSS 0.82%
- Veröffentlicht 23.11.2012 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Jboss Enterprise Application Platform Version5.1.0
Redhat ≫ Jboss Enterprise Application Platform Version5.1.1
Redhat ≫ Jboss Enterprise Application Platform Version5.2.0
Redhat ≫ Jboss Enterprise Application Platform Version5.2.1
Redhat ≫ Jboss Enterprise Brms Platform Version <= 5.2.0
Redhat ≫ Jboss Enterprise Soa Platform Version <= 5.2.0
Redhat ≫ Jboss Enterprise Soa Platform Version5.0.0
Redhat ≫ Jboss Enterprise Soa Platform Version5.0.1
Redhat ≫ Jboss Enterprise Soa Platform Version5.0.2
Redhat ≫ Jboss Enterprise Soa Platform Version5.1.0
Redhat ≫ Jboss Enterprise Soa Platform Version5.1.1
Redhat ≫ Jboss Enterprise Web Platform Version <= 5.1.1
Redhat ≫ Jboss Enterprise Web Platform Version5.1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.82% | 0.721 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:N/AC:H/Au:S/C:P/I:P/A:P
|