CVE-2012-3370
The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a…
Does this matter?
Lower severity and a low EPSS score (1.86%). Track it; it rarely justifies an emergency change on its own.
Description
The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to gain privileges as other users.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 1.86% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- redhat/jboss enterprise application platform · redhat/jboss enterprise web platform · redhat/jboss enterprise brms platform
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2013-0191.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0192.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0193.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0194.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0195.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0196.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0197.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0198.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0221.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0533.html
- http://secunia.com/advisories/51984Vendor Advisory
- http://secunia.com/advisories/52054Vendor Advisory
- http://securitytracker.com/id?1028042
- http://www.osvdb.org/89581
- http://www.securityfocus.com/bid/57550
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=836456
- https://exchange.xforce.ibmcloud.com/vulnerabilities/81513
- http://rhn.redhat.com/errata/RHSA-2013-0191.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0192.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0193.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0194.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0195.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0196.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0197.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0198.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0221.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0533.html
- http://secunia.com/advisories/51984Vendor Advisory
- http://secunia.com/advisories/52054Vendor Advisory
- http://securitytracker.com/id?1028042
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.