CVE-2012-3369

EUVD-2012-3343
The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
redhatjboss_enterprise_web_platform
5.2.0
redhatjboss_enterprise_application_platform
5.2.0
redhatjboss_enterprise_brms_platform
𝑥
≤ 5.3.0
𝑥
= Vulnerable software versions
Common Weakness Enumeration