JBoss Enterprise Application Platform CVE-2012-3369 Security Bypass Vulnerability
BID:57547
Info
JBoss Enterprise Application Platform CVE-2012-3369 Security Bypass Vulnerability
| Bugtraq ID: | 57547 |
| Class: | Unknown |
| CVE: |
CVE-2012-3369 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2012 12:00AM |
| Updated: | Feb 01 2013 04:40PM |
| Credit: | Carlo de Wolf of Red Hat |
| Vulnerable: |
Red Hat JBoss Enterprise Web Platform for RHEL 5 Server 5 Red Hat JBoss Enterprise Web Platform for RHEL 4ES 5 Red Hat JBoss Enterprise Web Platform for RHEL 4AS 5 Red Hat JBoss Enterprise BRMS Platform 5.1 Red Hat JBoss Enterprise Application Platform for RHEL 5 Server 5 Red Hat JBoss Enterprise Application Platform for RHEL 4ES 5 Red Hat JBoss Enterprise Application Platform for RHEL 4AS 5 |
| Not Vulnerable: | |
Discussion
JBoss Enterprise Application Platform CVE-2012-3369 Security Bypass Vulnerability
The JBoss Enterprise Application Platform is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass authentication and gain access to other user accounts. This may aid in further attacks.
The JBoss Enterprise Application Platform is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass authentication and gain access to other user accounts. This may aid in further attacks.
Exploit / POC
JBoss Enterprise Application Platform CVE-2012-3369 Security Bypass Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
JBoss Enterprise Application Platform CVE-2012-3369 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
JBoss Enterprise Application Platform CVE-2012-3369 Security Bypass Vulnerability
References:
References: