First published: Wed Dec 18 2019(Updated: )
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Application Server | =7.1.0 | |
Redhat Jboss Application Server | =7.1.1 | |
Redhat Jboss Enterprise Application Platform | =6.0.0-beta | |
debian/jbossas4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2312 is an Elevated Privileges issue in JBoss AS 7 Community Release due to improper implementation in the security context propagation.
CVE-2012-2312 allows a local user to obtain elevated privileges by reusing a threat from the thread pool that still retains the security context from the process last used.
CVE-2012-2312 has a severity rating of 7.8 (high).
JBoss AS 7 Community Release, Redhat Jboss Application Server 7.1.0, Redhat Jboss Application Server 7.1.1, and Redhat Jboss Enterprise Application Platform 6.0.0-beta are affected by CVE-2012-2312.
There is no known fix or remedy for CVE-2012-2312 at the moment.