CVE-2012-4572
low
CVSS v3
—
CVSS v2
3.7
VIR risk
3.7
Description
Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-1437.html
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-0834.html
Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2013-0833.html
Application impact
References
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.