Redhat

Jboss Enterprise Application Platform

240 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 51.29%
  • Veröffentlicht 05.02.2013 23:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentica...

  • EPSS 1.31%
  • Veröffentlicht 05.02.2013 23:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via ...

  • EPSS 1.67%
  • Veröffentlicht 05.02.2013 23:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a s...

  • EPSS 0.52%
  • Veröffentlicht 05.02.2013 23:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated ...

  • EPSS 0.05%
  • Veröffentlicht 05.02.2013 23:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password a...

  • EPSS 0.26%
  • Veröffentlicht 05.01.2013 00:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB)...

  • EPSS 0.27%
  • Veröffentlicht 05.01.2013 00:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, when using role-based authorization for Enterprise Java Beans (EJB) access, does not call the intended authorization modules, which prevents JACC permissions from being appl...

  • EPSS 0.82%
  • Veröffentlicht 23.11.2012 20:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm...

  • EPSS 0.72%
  • Veröffentlicht 23.11.2012 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which a...

  • EPSS 2.42%
  • Veröffentlicht 23.11.2012 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2....