PT-2012-3104 · Red Hat · Jbosswebrealm+5

Arun Babu Neelicattu

·

Publicado

2012-11-23

·

Atualizado

2017-08-29

·

CVE-2012-1167

CVSS v2.0

4.6

Média

VetorAV:N/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JBoss Enterprise Application Platform versions 5.1.x through 5.1.1 JBoss Enterprise Application Platform versions 5.2.x through 5.2.1 Web Platform versions 5.1.x through 5.1.1 BRMS Platform versions prior to 5.3.0 SOA Platform versions prior to 5.3.0
Description The issue arises when the JBoss Server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm. This configuration leads to improper checking of permissions created by the WebPermissionMapping class. As a result, remote authenticated users can access arbitrary applications.
Recommendations For JBoss Enterprise Application Platform versions 5.1.x through 5.1.1, update to version 5.1.2 or later. For JBoss Enterprise Application Platform versions 5.2.x through 5.2.1, update to version 5.2.2 or later. For Web Platform versions 5.1.x through 5.1.1, update to version 5.1.2 or later. For BRMS Platform versions prior to 5.3.0, update to version 5.3.0 or later. For SOA Platform versions prior to 5.3.0, update to version 5.3.0 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-1167
RHSA-2012:1026
RHSA-2012:1027

Produtos afetados

Brms Platform
Red Hat Jboss Enterprise Application Platform
Jboss Server
Jbosswebrealm
Soa Platform
Web Platform