CVE-2012-3370
- EPSS 1.67%
- Veröffentlicht 05.02.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a s...
CVE-2012-5478
- EPSS 0.52%
- Veröffentlicht 05.02.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated ...
CVE-2013-0218
- EPSS 0.05%
- Veröffentlicht 05.02.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password a...
CVE-2012-4549
- EPSS 0.26%
- Veröffentlicht 05.01.2013 00:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB)...
CVE-2012-4550
- EPSS 0.27%
- Veröffentlicht 05.01.2013 00:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, when using role-based authorization for Enterprise Java Beans (EJB) access, does not call the intended authorization modules, which prevents JACC permissions from being appl...
CVE-2012-1167
- EPSS 0.82%
- Veröffentlicht 23.11.2012 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm...
CVE-2011-4085
- EPSS 0.26%
- Veröffentlicht 23.11.2012 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which a...
CVE-2011-4605
- EPSS 2.42%
- Veröffentlicht 23.11.2012 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2....
CVE-2012-1154
- EPSS 0.26%
- Veröffentlicht 22.10.2012 23:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restr...
CVE-2009-5066
- EPSS 0.07%
- Veröffentlicht 13.08.2012 20:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.