CVE-2012-4572

CWE-2645 documents5 sources
Severity
3.7LOW
EPSS
0.2%
top 63.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 28
Latest updateMay 17

Description

Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.

CVSS vector

AV:L/AC:H/C:P/I:P/A:PExploitability: 1.9 | Impact: 6.4

🔴Vulnerability Details

2
GHSA
GHSA-w8gr-4mrr-7j77: Red Hat JBoss Enterprise Application Platform (EAP) before 62022-05-17
CVEList
CVE-2012-4572: Red Hat JBoss Enterprise Application Platform (EAP) before 62013-10-28

📋Vendor Advisories

1
Red Hat
JBoss: custom authorization module implementations shared between applications2013-05-20

💬Community

1
Bugzilla
CVE-2012-4572 JBoss: custom authorization module implementations shared between applications2012-11-01
CVE-2012-4572 (LOW CVSS 3.7) | Red Hat JBoss Enterprise Applicatio | cvebase.io