First published: Thu Jul 26 2012(Updated: )
When using multi-user authentication provided by the "allow-multiple-users" option for the datasource's connection pool together with a security domain, the credentials provided as arguments to the getConnection(uid,pwd) function are ignored. This means that a valid connection will be returned for an invalid credential. This could also mean that, provided the correct subject, a datasource connection can be obtained that which might belong to a privileged user. A fix for this issue is already available up-stream. The up-stream fix is located at [jira <a href="https://issues.jboss.org/browse/JBJCA-864">JBJCA-864</a>].
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jboss Ironjacamar | <=1.0.11 | |
maven/org.jboss.ironjacamar:ironjacamar-jdbc | <1.0.12.Final | 1.0.12.Final |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.