Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.
The MITRE CVE dictionary describes this issue as:
Find out more about CVE-2012-4572 from the MITRE CVE dictionary dictionary and NIST NVD.
Base Score | 3.7 |
---|---|
Base Metrics | AV:L/AC:H/Au:N/C:P/I:P/A:P |
Access Vector | Local |
Access Complexity | High |
Authentication | None |
Confidentiality Impact | Partial |
Integrity Impact | Partial |
Availability Impact | Partial |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 Server | RHSA-2013:0834 | 2013-05-20 |
Red Hat JBoss Portal Platform 6.1 | RHSA-2013:1437 | 2013-10-16 |
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 Server | RHSA-2013:0839 | 2013-05-20 |