PT-2012-3104 · Red Hat · Jbosswebrealm+5
Arun Babu Neelicattu
·
Publicado
2012-11-23
·
Atualizado
2017-08-29
·
CVE-2012-1167
CVSS v2.0
4.6
Média
| Vetor | AV:N/AC:H/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
JBoss Enterprise Application Platform versions 5.1.x through 5.1.1
JBoss Enterprise Application Platform versions 5.2.x through 5.2.1
Web Platform versions 5.1.x through 5.1.1
BRMS Platform versions prior to 5.3.0
SOA Platform versions prior to 5.3.0
Description
The issue arises when the JBoss Server is configured to use the JaccAuthorizationRealm and the
ignoreBaseDecision property is set to true on the JBossWebRealm. This configuration leads to improper checking of permissions created by the WebPermissionMapping class. As a result, remote authenticated users can access arbitrary applications.Recommendations
For JBoss Enterprise Application Platform versions 5.1.x through 5.1.1, update to version 5.1.2 or later.
For JBoss Enterprise Application Platform versions 5.2.x through 5.2.1, update to version 5.2.2 or later.
For Web Platform versions 5.1.x through 5.1.1, update to version 5.1.2 or later.
For BRMS Platform versions prior to 5.3.0, update to version 5.3.0 or later.
For SOA Platform versions prior to 5.3.0, update to version 5.3.0 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Brms Platform
Red Hat Jboss Enterprise Application Platform
Jboss Server
Jbosswebrealm
Soa Platform
Web Platform