CVE-2012-1167

Description

The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.

Risk Information

Base Score
4.6
MODERATE
Vector
AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.815

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 5.1.0Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 5.1.1Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 5.2.0Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 5.2.1Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234