VDB
RHSA-2012%3A1028
RHSA-2012%3A1028
PUBLISHED
CVSS 2.5999999046325684 LOW
The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method. NOTE: this vulnerability exists because of a CVE-2010-0738 regression.
Risk Scores
CVSS 2.0
2.5999999046325684
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | JBoss Enterprise BRMS Platform 5.3 |
Timeline
- Jun 22, 2012 CVE Published
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2012:1028 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=brms&downloadType=distributions advisory
- https://docs.redhat.com/docs/en-US/index.html advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=750422 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=766469 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=823392 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2012/rhsa-2012_1028.json advisory
- https://access.redhat.com/security/cve/CVE-2011-4085 advisory
- https://www.cve.org/CVERecord?id=CVE-2011-4085 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-4085 advisory
- https://access.redhat.com/security/cve/CVE-2011-4605 advisory
- https://www.cve.org/CVERecord?id=CVE-2011-4605 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-4605 advisory
- https://access.redhat.com/security/cve/CVE-2012-1167 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=802622 issue
- https://www.cve.org/CVERecord?id=CVE-2012-1167 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-1167 advisory
- https://access.redhat.com/security/cve/CVE-2012-2377 advisory
- https://www.cve.org/CVERecord?id=CVE-2012-2377 advisory
…and 1 more