CVE-2012-1167
Summary
| CVE | CVE-2012-1167 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-11-23 20:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:H/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Jboss Enterprise Application Platform | 5.1.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 5.1.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 5.2.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 5.2.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Brms Platform | All | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.0.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.0.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.0.2 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.1.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | 5.1.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Soa Platform | All | All | All | All |
| Application | Redhat | Jboss Enterprise Web Platform | 5.1.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Web Platform | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA50549 - Red Hat update for JBoss Enterprise Portal Platform - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| Security Advisory SA49635 - Red Hat update for JBoss Enterprise Application Platform and JBoss Enterprise Web Platform - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| rhn.redhat.com/errata/RHSA-2012-1125.html | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| JBoss CVE-2012-1167 Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| 802622 – (CVE-2012-1167) CVE-2012-1167 JBoss: authentication bypass when running under JACC with ignoreBaseDecision on JBossWebRealm | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| rhn.redhat.com/errata/RHSA-2012-1014.html | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| JBoss 'ignoreBaseDecision' Property May Let Remote Authenticated Users Bypass Access Controls - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Security Advisory SA49658 - Red Hat update for JBoss Enterprise Products - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | Vendor Advisory |
| rhn.redhat.com/errata/RHSA-2012-1028.html | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.