Beveiligingsadvies

CVE-2012-3369

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2013-02-05 23:11:00
Laatst bijgewerkt 2024-08-06 20:05:11
Toegewezen door redhat
CVSS-score geen score
Status PUBLISHED

Beschrijving

The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used.