CVE-2012-4572
Severity
3.7LOW
EPSS
0.2%
top 63.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 28
Latest updateMay 17
Description
Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.
CVSS vector
AV:L/AC:H/C:P/I:P/A:PExploitability: 1.9 | Impact: 6.4
Affected Packages2 packages
🔴Vulnerability Details
2📋Vendor Advisories
1💬Community
1Bugzilla▶
CVE-2012-4572 JBoss: custom authorization module implementations shared between applications↗2012-11-01