JBoss Enterprise Application Platform CVE-2012-3370 Security Bypass Vulnerability
BID:57550
Info
JBoss Enterprise Application Platform CVE-2012-3370 Security Bypass Vulnerability
| Bugtraq ID: | 57550 |
| Class: | Unknown |
| CVE: |
CVE-2012-3370 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2012 12:00AM |
| Updated: | Jun 29 2012 12:00AM |
| Credit: | Carlo de Wolf of Red Hat |
| Vulnerable: |
Red Hat JBoss Enterprise Web Platform for RHEL 5 Server 5 Red Hat JBoss Enterprise Web Platform for RHEL 4ES 5 Red Hat JBoss Enterprise Web Platform for RHEL 4AS 5 Red Hat JBoss Enterprise Application Platform for RHEL 5 Server 5 Red Hat JBoss Enterprise Application Platform for RHEL 4ES 5 Red Hat JBoss Enterprise Application Platform for RHEL 4AS 5 |
| Not Vulnerable: | |
Discussion
JBoss Enterprise Application Platform CVE-2012-3370 Security Bypass Vulnerability
The JBoss Enterprise Application Platform is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass authentication and gain access to other user accounts. This may aid in further attacks.
The JBoss Enterprise Application Platform is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass authentication and gain access to other user accounts. This may aid in further attacks.
Exploit / POC
JBoss Enterprise Application Platform CVE-2012-3370 Security Bypass Vulnerability
Attackers can exploit this issue through a browser.
Attackers can exploit this issue through a browser.
Solution / Fix
JBoss Enterprise Application Platform CVE-2012-3370 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
JBoss Enterprise Application Platform CVE-2012-3370 Security Bypass Vulnerability
References:
References: