CVE-2012-3369
published 2013-02-05CVE-2012-3369: The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA…
PriorityP426medium4CVSS 2.0
AVNACHAuNCPIPAN
EPSS
2.69%
84.2th percentile
The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_brms_platform | <= 5.3.0 | — |
| redhat | jboss_enterprise_web_platform | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hgmc-pjc5-rw9x: The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5
ghsa_unreviewed·2022-05-17
CVE-2012-3369 [MEDIUM] GHSA-hgmc-pjc5-rw9x: The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5
The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used.
Red Hat
JBoss: CallerIdentityLoginModule retaining password from previous call if a null password is provided
vendor_redhat·2013-01-24·CVSS 4.0
CVE-2012-3369 [MEDIUM] JBoss: CallerIdentityLoginModule retaining password from previous call if a null password is provided
JBoss: CallerIdentityLoginModule retaining password from previous call if a null password is provided
The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used.
Package: Security (Red Hat JBoss BRMS 5) - Affected
Package: PicketLink (Red Hat JBoss Portal 5) - Will not fix
Package: EAP (Red Hat JBoss SOA Platform 5) - Affected
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0533.htmlhttp://secunia.com/advisories/51984http://secunia.com/advisories/52054http://securitytracker.com/id?1028042http://www.securityfocus.com/bid/57547https://bugzilla.redhat.com/show_bug.cgi?id=836451https://exchange.xforce.ibmcloud.com/vulnerabilities/81512http://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0533.htmlhttp://secunia.com/advisories/51984http://secunia.com/advisories/52054http://securitytracker.com/id?1028042http://www.securityfocus.com/bid/57547https://bugzilla.redhat.com/show_bug.cgi?id=836451https://exchange.xforce.ibmcloud.com/vulnerabilities/81512
2013-02-05
Published