CVE-2012-3370
published 2013-02-05CVE-2012-3370: The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before…
PriorityP431medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.86%
76.9th percentile
The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to gain privileges as other users.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_brms_platform | <= 5.3.0 | — |
| redhat | jboss_enterprise_web_platform | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jrx8-2cjx-g9mh: The SecurityAssociation
ghsa_unreviewed·2022-05-17
CVE-2012-3370 [MEDIUM] GHSA-jrx8-2cjx-g9mh: The SecurityAssociation
The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to gain privileges as other users.
Red Hat
JBoss: SecurityAssociation.getCredential() will return the previous credential if no security context is provided
vendor_redhat·2013-01-24·CVSS 5.8
CVE-2012-3370 [MEDIUM] JBoss: SecurityAssociation.getCredential() will return the previous credential if no security context is provided
JBoss: SecurityAssociation.getCredential() will return the previous credential if no security context is provided
The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to gain privileges as other users.
Package: Security (Red Hat JBoss BRMS 5) - Affected
Package: PicketLink (Red Hat JBoss Portal 5) - Will not fix
Package: EAP (Red Hat JBoss SOA Platform 5) - Affected
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0533.htmlhttp://secunia.com/advisories/51984http://secunia.com/advisories/52054http://securitytracker.com/id?1028042http://www.osvdb.org/89581http://www.securityfocus.com/bid/57550https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=836456https://exchange.xforce.ibmcloud.com/vulnerabilities/81513http://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0221.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0533.htmlhttp://secunia.com/advisories/51984http://secunia.com/advisories/52054http://securitytracker.com/id?1028042http://www.osvdb.org/89581http://www.securityfocus.com/bid/57550https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=836456https://exchange.xforce.ibmcloud.com/vulnerabilities/81513
2013-02-05
Published