CVE-2013-0218
- EPSS 0.07%
- Published 05.02.2013 23:55:01
- Last modified 11.04.2025 00:51:21
The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password a...
CVE-2012-4549
- EPSS 0.26%
- Published 05.01.2013 00:55:02
- Last modified 11.04.2025 00:51:21
The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB)...
CVE-2012-4550
- EPSS 0.27%
- Published 05.01.2013 00:55:02
- Last modified 11.04.2025 00:51:21
JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, when using role-based authorization for Enterprise Java Beans (EJB) access, does not call the intended authorization modules, which prevents JACC permissions from being appl...
CVE-2012-1167
- EPSS 0.82%
- Published 23.11.2012 20:55:02
- Last modified 11.04.2025 00:51:21
The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm...
CVE-2011-4085
- EPSS 0.34%
- Published 23.11.2012 20:55:01
- Last modified 11.04.2025 00:51:21
The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which a...
CVE-2011-4605
- EPSS 2.42%
- Published 23.11.2012 20:55:01
- Last modified 11.04.2025 00:51:21
The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2....
CVE-2012-1154
- EPSS 0.34%
- Published 22.10.2012 23:55:05
- Last modified 11.04.2025 00:51:21
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restr...
CVE-2009-5066
- EPSS 0.07%
- Published 13.08.2012 20:55:01
- Last modified 11.04.2025 00:51:21
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
CVE-2011-4314
- EPSS 1.29%
- Published 27.01.2012 15:55:04
- Last modified 11.04.2025 00:51:21
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is...
CVE-2011-4608
- EPSS 0.74%
- Published 27.01.2012 15:55:04
- Last modified 11.04.2025 00:51:21
mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide malicious content, hijack sess...