CVE-2012-3369
MEDIUM severity · CVSS 4 · CWE-264
4CVSS MEDIUM
Summary
The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used.
Impact & exploitability
Attack vectorNetwork
Attack complexityHigh
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impactNone
Exploit probability (EPSS)3%
AV:N/AC:H/Au:N/C:P/I:P/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://rhn.redhat.com/errata/RHSA-2013-0191.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-0192.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-0193.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-0194.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-0195.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-0196.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-0197.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2013-0198.htmlAdvisory