CVE-2012-3369

CWE-2645 documents5 sources
Severity
4.0MEDIUM
EPSS
1.3%
top 20.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 5
Latest updateMay 17

Description

The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used.

CVSS vector

AV:N/AC:H/C:P/I:P/A:NExploitability: 4.9 | Impact: 4.9

🔴Vulnerability Details

2
GHSA
GHSA-hgmc-pjc5-rw9x: The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 52022-05-17
CVEList
CVE-2012-3369: The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 52013-02-05

📋Vendor Advisories

1
Red Hat
JBoss: CallerIdentityLoginModule retaining password from previous call if a null password is provided2013-01-24

💬Community

1
Bugzilla
CVE-2012-3369 JBoss: CallerIdentityLoginModule retaining password from previous call if a null password is provided2012-06-29
CVE-2012-3369 (MEDIUM CVSS 4) | The CallerIdentityLoginModule in JB | cvebase.io