CVE-2012-0818

medium
Published 2012-11-23 · Modified 2024-12-03
CVSS v3
CVSS v2
5.0
VIR risk
5.0

Description

Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://issues.jboss.org/browse/RESTEASY-637

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/50084

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/47832

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/47818

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2012-1125.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2012-1059.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2012-1058.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2012-1057.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2012-1056.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2012-0519.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2012-0441.html

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.jboss.resteasy:resteasy-client<2.3.12.3.1

Application impact

VendorProductVersionsFixed
redhat redhatresteasy{"endIncluding":"2.3.0"}
redhat redhatresteasy1.0.0
redhat redhatresteasy1.0.1
redhat redhatresteasy1.0.2
redhat redhatresteasy1.1
redhat redhatresteasy1.2
redhat redhatresteasy2.0.0
redhat redhatresteasy2.0.1
redhat redhatresteasy2.1.0
redhat redhatresteasy2.2.0
redhat redhatresteasy2.2.1
redhat redhatresteasy2.2.2
redhat redhatresteasy2.2.3

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.