CVE-2012-1167
published 2012-11-23CVE-2012-1167: The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and…
PriorityP426medium4.6CVSS 2.0
AVNACHAuSCPIPAP
EPSS
1.60%
73.1th percentile
The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_brms_platform | <= 5.2.0 | — |
| redhat | jboss_enterprise_soa_platform | <= 5.2.0 | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_web_platform | <= 5.1.1 | — |
| redhat | jboss_enterprise_web_platform | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:N/AC:H/Au:S/C:P/I:P/A:P
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9f9q-j576-jp97: The JBoss Server in JBoss Enterprise Application Platform 5
ghsa_unreviewed·2022-05-17
CVE-2012-1167 [MEDIUM] GHSA-9f9q-j576-jp97: The JBoss Server in JBoss Enterprise Application Platform 5
The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.
Red Hat
JBoss: authentication bypass when running under JACC with ignoreBaseDecision on JBossWebRealm
vendor_redhat·2012-06-12·CVSS 4.6
CVE-2012-1167 [MEDIUM] JBoss: authentication bypass when running under JACC with ignoreBaseDecision on JBossWebRealm
JBoss: authentication bypass when running under JACC with ignoreBaseDecision on JBossWebRealm
The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.
Package: Security (Red Hat JBoss BRMS 5) - Affected
Package: Requirements (Red Hat JBoss Portal 5) - Affected
Package: Security (Red Hat JBoss SOA Platform 5) - Affected
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-1013.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1014.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1026.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1027.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1028.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1125.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1232.htmlhttp://secunia.com/advisories/49635http://secunia.com/advisories/49658http://secunia.com/advisories/50549http://securitytracker.com/id?1027501http://www.securityfocus.com/bid/54089https://bugzilla.redhat.com/show_bug.cgi?id=802622https://exchange.xforce.ibmcloud.com/vulnerabilities/76680http://rhn.redhat.com/errata/RHSA-2012-1013.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1014.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1026.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1027.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1028.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1125.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1232.htmlhttp://secunia.com/advisories/49635http://secunia.com/advisories/49658http://secunia.com/advisories/50549http://securitytracker.com/id?1027501http://www.securityfocus.com/bid/54089https://bugzilla.redhat.com/show_bug.cgi?id=802622https://exchange.xforce.ibmcloud.com/vulnerabilities/76680
2012-11-23
Published