First published: Fri Jun 29 2012(Updated: )
The CallerIdentityLoginModule will retain the password from the previous call if a null password is provided, and pass the provided username along with the previously provided password as credentials for the current Principal. If the CallerIdentityLoginModule was utilized in a way that allowed a user to authenticate with a null password (rather than an empty string), then a remote attacker could exploit this flaw to hijack the credentials of a previously authenticated user if they knew their username, and were able to time their login attempt so it immediately followed a call made by the previously authenticated user.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Enterprise Web Platform | =5.2.0 | |
Redhat Jboss Enterprise Application Platform | =5.2.0 | |
Redhat Jboss Enterprise Brms Platform | <=5.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.