Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Derek Horton

Pesquisador deRed Hat
#49776de 53,633
4.9CVSS total
Vulnerabilidades · 1
PT-2013-1800
4.9
2013-02-05
Red Hat · Jboss Soa Platform · CVE-2012-5478
**Name of the Vulnerable Software and Affected Versions** JBoss Enterprise Application Platform versions prior to 5.2.0 JBoss Web Platform versions prior to 5.2.0 JBoss BRMS Platform versions prior to 5.3.1 JBoss SOA Platform versions prior to 5.3.1 **Description** The issue concerns improper access restriction in the AuthorizationInterceptor, allowing remote authenticated users to bypass intended role restrictions. This enables them to perform arbitrary JMX operations, although the specific vectors are not specified. **Recommendations** For JBoss Enterprise Application Platform versions prior to 5.2.0, update to version 5.2.0 or later. For JBoss Web Platform versions prior to 5.2.0, update to version 5.2.0 or later. For JBoss BRMS Platform versions prior to 5.3.1, update to version 5.3.1 or later. For JBoss SOA Platform versions prior to 5.3.1, update to version 5.3.1 or later.