CVE-2012-2312
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used,…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.29%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.29% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- redhat/jboss application server · redhat/jboss enterprise application platform
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/cve-2012-2312Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2312Issue Tracking, Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2012-2312Third Party Advisory
- https://access.redhat.com/security/cve/cve-2012-2312Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-2312Issue Tracking, Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2012-2312Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.