CVE-2012-4550
published 2013-01-05CVE-2012-4550: A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.12%
79.8th percentile
A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CVE-2012-4550: JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6
vendor_redhat·2013-01-05·CVSS 6.4
CVE-2012-4550 [MEDIUM] CWE-280 CVE-2012-4550: JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6
JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, when using role-based authorization for Enterprise Java Beans (EJB) access, does not call the intended authorization modules, which prevents JACC permissions from being applied and allows remote attackers to obtain access to the EJB.
A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Ha
VulDB
Red Hat JBoss Enterprise Application Platform 6 EL4 mod_negotiation processInvocation access control (Bug 870871 / Nessus ID 64071)
vuldb·2026-05-15·CVSS 5.3
CVE-2012-4550 [MEDIUM] Red Hat JBoss Enterprise Application Platform 6 EL4 mod_negotiation processInvocation access control (Bug 870871 / Nessus ID 64071)
A vulnerability was found in Red Hat JBoss Enterprise Application Platform 6 EL4 and classified as critical. This vulnerability affects the function processInvocation of the component mod_negotiation. Executing a manipulation can lead to improper access controls.
This vulnerability is handled as CVE-2012-4550. The attack can be executed remotely. Additionally, an exploit exists.
It is suggested to upgrade the affected component.
GHSA
GHSA-gg53-v4gc-qv5q: JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6
ghsa_unreviewed·2022-05-17
CVE-2012-4550 [MEDIUM] GHSA-gg53-v4gc-qv5q: JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6
JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, when using role-based authorization for Enterprise Java Beans (EJB) access, does not call the intended authorization modules, which prevents JACC permissions from being applied and allows remote attackers to obtain access to the EJB.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-1591.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1592.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1594.htmlhttp://secunia.com/advisories/51607https://access.redhat.com/errata/RHSA-2012:1591https://access.redhat.com/errata/RHSA-2012:1592https://access.redhat.com/errata/RHSA-2012:1594https://access.redhat.com/security/cve/CVE-2012-4550http://rhn.redhat.com/errata/RHSA-2012-1591.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1592.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1594.htmlhttp://secunia.com/advisories/51607
2013-01-05
Published