CVE-2012-4550
JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, when using role-based authorization for Enterprise Java Beans (EJB) access, does not call the intended authorization modules, which prevents JACC permissions from being applied and allows remote attackers to obtain access to the EJB.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.27%
- CWE
- CWE-280
- Published
- 2013-01-05
- Last modified
- 2026-05-14
Affected products
- n/a n/a
- Red Hat Red Hat JBoss Enterprise Application Platform 6 for RHEL 5
- Red Hat Red Hat JBoss Enterprise Application Platform 6 for RHEL 5
- Red Hat Red Hat JBoss Enterprise Application Platform 6 for RHEL 5
- Red Hat Red Hat JBoss Enterprise Application Platform 6 for RHEL 5
- Red Hat Red Hat JBoss Enterprise Application Platform 6 for RHEL 5
- Red Hat Red Hat JBoss Enterprise Application Platform 6 for RHEL 5
- Red Hat Red Hat JBoss Enterprise Application Platform 6 for RHEL 5
Weakness type
Related vulnerabilities
- CVE-2024-25108 — Insufficient authorization allowing elevated access to resources in pixelfed
- CVE-2024-46874 — Ruijie Reyee OS Improper Handling of Insufficient Permissions or Privileges
- CVE-2025-31173 — Memory write permission bypass vulnerability in the kernel futex module Impact: Successful exploitation of this vulnerab
- CVE-2025-27025 — Improper File Access in Infinera G42
- CVE-2026-2123 — Privilege escalation vulnerability in Operations Agent
- CVE-2022-4863 — Improper Handling of Insufficient Permissions or Privileges in usememos/memos
- CVE-2024-51459 — IBM InfoSphere Server Information command execution
- CVE-2026-23857 — Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insufficient P