CVE-2012-1167

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.6 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:S/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
redhatjboss_enterprise_application_platform
5.1.0
redhatjboss_enterprise_application_platform
5.1.1
redhatjboss_enterprise_application_platform
5.2.0
redhatjboss_enterprise_application_platform
5.2.1
redhatjboss_enterprise_brms_platform
𝑥
≤ 5.2.0
redhatjboss_enterprise_soa_platform
𝑥
≤ 5.2.0
redhatjboss_enterprise_soa_platform
5.0.0
redhatjboss_enterprise_soa_platform
5.0.1
redhatjboss_enterprise_soa_platform
5.0.2
redhatjboss_enterprise_soa_platform
5.1.0
redhatjboss_enterprise_soa_platform
5.1.1
redhatjboss_enterprise_web_platform
𝑥
≤ 5.1.1
redhatjboss_enterprise_web_platform
5.1.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jbossas4
precise
not-affected
oneiric
not-affected
natty
not-affected
lucid
not-affected
hardy
not-affected
Common Weakness Enumeration