SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-4709

The popSubjectContext method in the SecurityAssociation class in JBoss Enterprise Java Beans (EJB) 3.0 RC3 maintains the threadPrincipal and threadCredential values from a previous client's authentication after termination of a client session, which…

MEDIUM 5.0EPSS 2.23%

Does this matter?

Lower severity and a low EPSS score (2.23%). Track it; it rarely justifies an emergency change on its own.

Description

The popSubjectContext method in the SecurityAssociation class in JBoss Enterprise Java Beans (EJB) 3.0 RC3 maintains the threadPrincipal and threadCredential values from a previous client's authentication after termination of a client session, which allows remote attackers to gain the roles of an arbitrary previous client who had the same JBoss server thread.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
2.23% probability · 82th percentile
CISA KEV
Not listed
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.