A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs.
References
| Link | Resource |
|---|---|
| http://rhn.redhat.com/errata/RHSA-2012-1591.html | Vendor Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-1592.html | Vendor Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-1594.html | Vendor Advisory |
| http://secunia.com/advisories/51607 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2012:1591 | |
| https://access.redhat.com/errata/RHSA-2012:1592 | |
| https://access.redhat.com/errata/RHSA-2012:1594 | |
| https://access.redhat.com/security/cve/CVE-2012-4550 | |
| http://rhn.redhat.com/errata/RHSA-2012-1591.html | Vendor Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-1592.html | Vendor Advisory |
| http://rhn.redhat.com/errata/RHSA-2012-1594.html | Vendor Advisory |
| http://secunia.com/advisories/51607 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2013-01-05 00:55
Updated : 2026-06-16 23:45
NVD link : CVE-2012-4550
Mitre link : CVE-2012-4550
CVE.ORG link : CVE-2012-4550
JSON object : View
Products Affected
redhat
- jboss_enterprise_application_platform
