CVE-2012-1167
Last modified
CVE-2012-1167 is a vulnerability of currently unknown severity. The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.. EPSS estimates a 1.60% chance of exploitation in the next 30 days.
Description
The JBoss Server in JBoss Enterprise Application Platform 5.1.x before 5.1.2 and 5.2.x before 5.2.2, Web Platform before 5.1.2, BRMS Platform before 5.3.0, and SOA Platform before 5.3.0, when the server is configured to use the JaccAuthorizationRealm and the ignoreBaseDecision property is set to true on the JBossWebRealm, does not properly check the permissions created by the WebPermissionMapping class, which allows remote authenticated users to access arbitrary applications.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Enterprise Application Platform | 5.1.0 |
| Redhat | Jboss Enterprise Application Platform | 5.1.1 |
| Redhat | Jboss Enterprise Application Platform | 5.2.0 |
| Redhat | Jboss Enterprise Application Platform | 5.2.1 |
| Redhat | Jboss Enterprise Brms Platform | <= 5.2.0 |
| Redhat | Jboss Enterprise Soa Platform | <= 5.2.0 |
| Redhat | Jboss Enterprise Soa Platform | 5.0.0 |
| Redhat | Jboss Enterprise Soa Platform | 5.0.1 |
| Redhat | Jboss Enterprise Soa Platform | 5.0.2 |
| Redhat | Jboss Enterprise Soa Platform | 5.1.0 |
| Redhat | Jboss Enterprise Soa Platform | 5.1.1 |
| Redhat | Jboss Enterprise Web Platform | <= 5.1.1 |
| Redhat | Jboss Enterprise Web Platform | 5.1.0 |
References
- http://rhn.redhat.com/errata/RHSA-2012-1013.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1014.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1026.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1027.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1125.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1232.htmlVendor Advisory
- http://secunia.com/advisories/49635Vendor Advisory
- http://secunia.com/advisories/49658Vendor Advisory
- http://secunia.com/advisories/50549Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1013.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1014.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1026.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1027.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1125.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1232.htmlVendor Advisory
- http://secunia.com/advisories/49635Vendor Advisory
- http://secunia.com/advisories/49658Vendor Advisory
- http://secunia.com/advisories/50549Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-1167?
How severe is CVE-2012-1167?
How do I fix CVE-2012-1167?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-1161Moodle before 2.2.2: Course information leak via hidden cour…4.3
- CVE-2012-1162Heap-based buffer overflow in the _zip_readcdir function in …
- CVE-2012-1163Integer overflow in the _zip_readcdir function in zip_open.c…
- CVE-2012-1164slapd in OpenLDAP before 2.4.30 allows remote attackers to c…
- CVE-2012-1165The mime_param_cmp function in crypto/asn1/asn_mime.c in Ope…
- CVE-2012-1166The default keybindings for wwm in LTSP Display Manager (ldm…
- CVE-2012-1168Moodle before 2.2.2 has a password and web services issue wh…8.2
- CVE-2012-1169Moodle before 2.2.2 has Personal information disclosure, whe…5.3
- CVE-2012-1170Moodle before 2.2.2 has an external enrolment plugin context…7.5
- CVE-2012-1171The libxml RSHUTDOWN function in PHP 5.x allows remote attac…
- CVE-2012-1172The file-upload implementation in rfc1867.c in PHP before 5.…
- CVE-2012-1173Multiple integer overflows in tiff_getimage.c in LibTIFF 3.9…
Are you affected by CVE-2012-1167?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
