First published: Thu Jan 23 2020(Updated: )
EJB method in Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 5; Red Hat JBoss Operations Network 3.1; Red Hat JBoss Portal 4 and 5; Red Hat JBoss SOA Platform 4.2, 4.3, and 5; in Red Hat JBoss Enterprise Web Server 1 ignores roles specified using the @RunAs annotation.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Brms | =5 | |
Redhat Jboss Enterprise Application Platform | =5.0.0 | |
Redhat Jboss Enterprise Web Server | =1.0.0 | |
Redhat Jboss Operations Network | =3.1 | |
Redhat Jboss Portal | =4.0.0 | |
Redhat Jboss Portal | =5.0.0 | |
Redhat Jboss Soa Platform | =4.2 | |
Redhat Jboss Soa Platform | =4.3 | |
Redhat Jboss Soa Platform | =5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2012-5626 is high with a severity value of 7.5.
Red Hat JBoss BRMS 5, Red Hat JBoss Enterprise Application Platform 5, Red Hat JBoss Operations Network 3.1, Red Hat JBoss Portal 4 and 5, Red Hat JBoss SOA Platform 4.2, 4.3, and 5, and Red Hat JBoss Enterprise Web Server 1 are affected by CVE-2012-5626.
CVE-2012-5626 vulnerability in Red Hat JBoss ignores roles specified using the @RunAs annotation.
To fix CVE-2012-5626, it is recommended to update to the latest version of the affected software or apply the necessary patches provided by Red Hat.
You can find more information about CVE-2012-5626 on the Red Hat security advisory page at https://access.redhat.com/security/cve/cve-2012-5626.