A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs.
References
| Link | Resource |
|---|---|
| http://rhn.redhat.com/errata/RHSA-2012-1591.html | Vendor Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-1592.html | Vendor Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-1594.html | Vendor Advisory |
| http://secunia.com/advisories/51607 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2012:1591 | |
| https://access.redhat.com/errata/RHSA-2012:1592 | |
| https://access.redhat.com/errata/RHSA-2012:1594 | |
| https://access.redhat.com/security/cve/CVE-2012-4550 | |
| http://rhn.redhat.com/errata/RHSA-2012-1591.html | Vendor Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-1592.html | Vendor Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-1594.html | Vendor Advisory |
| http://secunia.com/advisories/51607 | Vendor Advisory |
Configurations
History
14 May 2026, 23:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CVSS |
v2 : v3 : |
v2 : 6.4
v3 : 5.3 |
| CWE | CWE-280 | |
| Summary | (en) A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs. |
21 Nov 2024, 01:43
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://rhn.redhat.com/errata/RHSA-2012-1591.html - Vendor Advisory | |
| References | () http://rhn.redhat.com/errata/RHSA-2012-1592.html - Vendor Advisory | |
| References | () http://rhn.redhat.com/errata/RHSA-2012-1594.html - Vendor Advisory | |
| References | () http://secunia.com/advisories/51607 - Vendor Advisory |
Information
Published : 2013-01-05 00:55
Updated : 2026-05-14 23:16
NVD link : CVE-2012-4550
Mitre link : CVE-2012-4550
CVE.ORG link : CVE-2012-4550
JSON object : View
Products Affected
redhat
- jboss_enterprise_application_platform
