CVE-2012-3370

CWE-2645 documents5 sources
Severity
5.8MEDIUM
EPSS
1.7%
top 17.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 5
Latest updateMay 17

Description

The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to gain privileges as other users.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9

🔴Vulnerability Details

2
GHSA
GHSA-jrx8-2cjx-g9mh: The SecurityAssociation2022-05-17
CVEList
CVE-2012-3370: The SecurityAssociation2013-02-05

📋Vendor Advisories

1
Red Hat
JBoss: SecurityAssociation.getCredential() will return the previous credential if no security context is provided2013-01-24

💬Community

1
Bugzilla
CVE-2012-3370 JBoss: SecurityAssociation.getCredential() will return the previous credential if no security context is provided2012-06-29
CVE-2012-3370 (MEDIUM CVSS 5.8) | The SecurityAssociation.getCredenti | cvebase.io