CVE-2012-3369

Publication date

2013-02-05 23:11:00

Family

redhat

State

PUBLISHED

Description

The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous users password to be used.