CVE-2012-4550

medium

Description

A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs.

References

https://access.redhat.com/security/cve/CVE-2012-4550

https://access.redhat.com/errata/RHSA-2012:1594

https://access.redhat.com/errata/RHSA-2012:1592

https://access.redhat.com/errata/RHSA-2012:1591

http://secunia.com/advisories/51607

http://rhn.redhat.com/errata/RHSA-2012-1594.html

http://rhn.redhat.com/errata/RHSA-2012-1592.html

http://rhn.redhat.com/errata/RHSA-2012-1591.html

Details

Source: Mitre, NVD

Published: 2013-01-05

Updated: 2026-05-14

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00273