MEDIUM · 4.6

CVE-2012-1167

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the serv...

Vulnerability Description

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.

CVSS Score

4.6

MEDIUM

AV:N/AC:H/Au:S/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
RedhatJboss Enterprise Application Platform5.1.0
RedhatJboss Enterprise Brms Platform<= 5.2.0
RedhatJboss Enterprise Soa Platform<= 5.2.0
RedhatJboss Enterprise Web Platform<= 5.1.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2012-1167?

CVE-2012-1167 is a vulnerability with a CVSS score of 4.6 (MEDIUM). The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the serv...

How severe is CVE-2012-1167?

CVE-2012-1167 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2012-1167?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Jboss Enterprise Application Platform, Redhat Jboss Enterprise Brms Platform, Redhat Jboss Enterprise Soa Platform, Redhat Jboss Enterprise Web Platform.