PT-2020-7262 · Red Hat · Red Hat Jboss Brms+5
Published
2020-01-23
·
Updated
2020-02-05
·
CVE-2012-5626
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Red Hat JBoss BRMS version 5
Red Hat JBoss Enterprise Application Platform version 5
Red Hat JBoss Operations Network version 3.1
Red Hat JBoss Portal versions 4 and 5
Red Hat JBoss SOA Platform versions 4.2, 4.3, and 5
Red Hat JBoss Enterprise Web Server version 1
Description:
The issue concerns an EJB method that ignores roles specified using the
@RunAs annotation, potentially leading to unauthorized access.Recommendations:
For Red Hat JBoss BRMS version 5, update the EJB method to properly handle roles specified using the
@RunAs annotation.
For Red Hat JBoss Enterprise Application Platform version 5, modify the application to enforce role-based access control.
For Red Hat JBoss Operations Network version 3.1, restrict access to sensitive resources until the issue is resolved.
For Red Hat JBoss Portal versions 4 and 5, apply additional security measures to prevent unauthorized access.
For Red Hat JBoss SOA Platform versions 4.2, 4.3, and 5, reconfigure the platform to correctly implement role-based access control.
For Red Hat JBoss Enterprise Web Server version 1, consider disabling the vulnerable EJB method until a proper fix is available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat Jboss Brms
Red Hat Jboss Enterprise Application Platform
Red Hat Jboss Enterprise Web Server
Red Hat Jboss Operations Network
Red Hat Jboss Portal
Red Hat Jboss Soa Platform