CVE-2012-5478

CWE-2645 documents5 sources
Severity
4.9MEDIUM
EPSS
0.5%
top 33.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 5
Latest updateMay 17

Description

The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated users to bypass intended role restrictions and perform arbitrary JMX operations via unspecified vectors.

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 6.8 | Impact: 4.9

🔴Vulnerability Details

2
GHSA
GHSA-w372-6384-f8p5: The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 52022-05-17
CVEList
CVE-2012-5478: The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 52013-02-05

📋Vendor Advisories

1
Red Hat
JBoss: AuthorizationInterceptor allows JMX operation to proceed despite authorization failure2013-01-24

💬Community

1
Bugzilla
CVE-2012-5478 JBoss: AuthorizationInterceptor allows JMX operation to proceed despite authorization failure2012-11-08