CVE-2012-4549
published 2013-01-05CVE-2012-4549: A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor`…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
1.31%
67.4th percentile
A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are defined for an Enterprise Java Beans (EJB) method invocation. This allows attackers to bypass intended access restrictions for EJB methods, leading to unauthorized access to sensitive functionalities.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | <= 6.0.0 | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CVE-2012-4549: The processInvocation function in org
vendor_redhat·2013-01-05·CVSS 5.8
CVE-2012-4549 [MEDIUM] CWE-266 CVE-2012-4549: The processInvocation function in org
The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.
A flaw was found in JBoss Enterprise Application Platform. The `processInvocation` function within the `org.jboss.as.ejb3.security.AuthorizationInterceptor` component incorrectly authorizes all requests when no roles are defined for an Enterprise Java Beans (EJB) method invocation. This allows attackers to bypass intended access restrictions for EJB methods, leading to unauthorized access to sensitive functionalities.
Mitigation: Mitigation for
VulDB
Red Hat JBoss Enterprise Application Platform 6 EL4 mod_negotiation processInvocation access control (Bug 870868 / Nessus ID 64071)
vuldb·2026-05-15·CVSS 6.5
CVE-2012-4549 [MEDIUM] Red Hat JBoss Enterprise Application Platform 6 EL4 mod_negotiation processInvocation access control (Bug 870868 / Nessus ID 64071)
A vulnerability was found in Red Hat JBoss Enterprise Application Platform 6 EL4. It has been classified as critical. This issue affects the function processInvocation of the component mod_negotiation. The manipulation leads to improper access controls.
This vulnerability is uniquely identified as CVE-2012-4549. The attack is possible to be carried out remotely. Moreover, an exploit is present.
Upgrading the affected component is recommended.
GHSA
GHSA-4crg-m9w3-g9fc: The processInvocation function in org
ghsa_unreviewed·2022-05-17
CVE-2012-4549 [MEDIUM] GHSA-4crg-m9w3-g9fc: The processInvocation function in org
The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-1591.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1592.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1594.htmlhttp://secunia.com/advisories/51607https://access.redhat.com/errata/RHSA-2012:1591https://access.redhat.com/errata/RHSA-2012:1592https://access.redhat.com/errata/RHSA-2012:1594https://access.redhat.com/security/cve/CVE-2012-4549http://rhn.redhat.com/errata/RHSA-2012-1591.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1592.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1594.htmlhttp://secunia.com/advisories/51607
2013-01-05
Published