Vulnerability Description
The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Enterprise Application Platform | 5.1.0 |
| Redhat | Jboss Enterprise Brms Platform | <= 5.2.0 |
| Redhat | Jboss Enterprise Soa Platform | <= 5.2.0 |
| Redhat | Jboss Enterprise Web Platform | <= 5.1.1 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2012-1013.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1014.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1026.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1027.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1028.html
- http://rhn.redhat.com/errata/RHSA-2012-1125.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1232.htmlVendor Advisory
- http://secunia.com/advisories/49635Vendor Advisory
- http://secunia.com/advisories/49658Vendor Advisory
- http://secunia.com/advisories/50549Vendor Advisory
- http://securitytracker.com/id?1027501
- http://www.securityfocus.com/bid/54089
- https://bugzilla.redhat.com/show_bug.cgi?id=802622
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76680
- http://rhn.redhat.com/errata/RHSA-2012-1013.htmlVendor Advisory
FAQ
What is CVE-2012-1167?
CVE-2012-1167 is a vulnerability with a CVSS score of 4.6 (MEDIUM). The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the serv...
How severe is CVE-2012-1167?
CVE-2012-1167 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-1167?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Jboss Enterprise Application Platform, Redhat Jboss Enterprise Brms Platform, Redhat Jboss Enterprise Soa Platform, Redhat Jboss Enterprise Web Platform.