CVE-2012-4550
- EPSS 2.12%
- Veröffentlicht 05.01.2013 00:55:02
- Zuletzt bearbeitet 16.06.2026 23:45:20
A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract...
CVE-2012-1167
- EPSS 1.6%
- Veröffentlicht 23.11.2012 20:55:02
- Zuletzt bearbeitet 16.06.2026 23:39:10
The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm...
CVE-2011-4085
- EPSS 2.95%
- Veröffentlicht 23.11.2012 20:55:01
- Zuletzt bearbeitet 16.06.2026 23:34:23
The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which a...
CVE-2011-4605
- EPSS 3.52%
- Veröffentlicht 23.11.2012 20:55:01
- Zuletzt bearbeitet 16.06.2026 23:35:07
The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2....
CVE-2012-1154
- EPSS 2.59%
- Veröffentlicht 22.10.2012 23:55:05
- Zuletzt bearbeitet 16.06.2026 23:39:08
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restr...
CVE-2009-5066
- EPSS 0.39%
- Veröffentlicht 13.08.2012 20:55:01
- Zuletzt bearbeitet 16.06.2026 23:14:55
twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.
CVE-2011-4314
- EPSS 3.2%
- Veröffentlicht 27.01.2012 15:55:04
- Zuletzt bearbeitet 16.06.2026 23:34:45
message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is...
CVE-2011-4608
- EPSS 3.2%
- Veröffentlicht 27.01.2012 15:55:04
- Zuletzt bearbeitet 16.06.2026 23:35:08
mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide malicious content, hijack sess...
CVE-2011-2196
- EPSS 2.59%
- Veröffentlicht 27.07.2011 02:55:01
- Zuletzt bearbeitet 16.06.2026 23:30:54
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enter...
CVE-2011-1484
- EPSS 2.29%
- Veröffentlicht 27.07.2011 02:42:27
- Zuletzt bearbeitet 16.06.2026 23:29:28
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly re...