SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-3370

The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a…

MEDIUM 5.8EPSS 1.86%

Does this matter?

Lower severity and a low EPSS score (1.86%). Track it; it rarely justifies an emergency change on its own.

Description

The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to gain privileges as other users.

CVSS 2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS
1.86% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-264
Affected
redhat/jboss enterprise application platform · redhat/jboss enterprise web platform · redhat/jboss enterprise brms platform
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.