CVE-2012-5626
published 2020-01-23CVE-2012-5626: EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.91%
56.0th percentile
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | jboss_brms | — | — |
| red_hat | jboss_enterprise_application_platform | — | — |
| red_hat | jboss_enterprise_web_server | — | — |
| red_hat | jboss_operations_network | — | — |
| red_hat | jboss_portal | — | — |
| red_hat | jboss_portal | — | — |
| red_hat | jboss_soa_platform | — | — |
| red_hat | jboss_soa_platform | — | — |
| red_hat | jboss_soa_platform | — | — |
| redhat | jboss_brms | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_web_server | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_portal | — | — |
| redhat | jboss_portal | — | — |
| redhat | jboss_soa_platform | — | — |
| redhat | jboss_soa_platform | — | — |
| redhat | jboss_soa_platform | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jmm8-g2w4-4fc4: EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3
ghsa_unreviewed·2022-04-23
CVE-2012-5626 [MEDIUM] GHSA-jmm8-g2w4-4fc4: EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.
Red Hat
JBoss - EJB method invocation ignores roles specified using the @RunAs annotation
vendor_redhat·2015-02-06·CVSS 7.5
CVE-2012-5626 [HIGH] JBoss - EJB method invocation ignores roles specified using the @RunAs annotation
JBoss - EJB method invocation ignores roles specified using the @RunAs annotation
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.
Statement: Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 4 and 5; Red Hat JBoss Enterprise Portal Platform 5; Red Hat JBoss Enterprise SOA Platform 4 and 5; and Red Hat JBoss Enterprise Web Platform 5 are now in Phase 3, Extended Life Support, of their respective life cycles. This issue has been rated as having Low security impact and is not currently planned to be addressed in future updates. For ad
No detection rules found.
No public exploits indexed.
2020-01-23
Published