CVE-2012-4550
This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs.
Does this matter?
Lower severity and a low EPSS score (2.12%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 2.12% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-280, CWE-264
- Affected
- redhat/jboss enterprise application platform
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2012-1591.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1592.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1594.htmlVendor Advisory
- http://secunia.com/advisories/51607Vendor Advisory
- https://access.redhat.com/errata/RHSA-2012:1591
- https://access.redhat.com/errata/RHSA-2012:1592
- https://access.redhat.com/errata/RHSA-2012:1594
- https://access.redhat.com/security/cve/CVE-2012-4550
- http://rhn.redhat.com/errata/RHSA-2012-1591.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1592.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1594.htmlVendor Advisory
- http://secunia.com/advisories/51607Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.