CVE-2012-4572 PUBLISHED CVSS 3.700000047683716 LOW

Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.

EPSS 0.15% · 35.9th percentile

Risk Scores

CVSS v2.0
3.700000047683716
EPSS Score
0.15%
35.9th percentile

Affected Products

VendorProductVersions
redhatjboss_enterprise_application_platform6.0.0, 0, 4.2.0
n/an/an/a
redhatjboss_enterprise_portal_platform0, 4.3.0, 5.0.0

Timeline

References

Open in Interactive Console →