The AuthorizationInterceptor in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 does not properly restrict access, which allows remote authenticated users to bypass intended role restrictions and perform arbitrary JMX operations via unspecified vectors.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2013-02-05 23:55
Updated : 2025-04-11 00:51
NVD link : CVE-2012-5478
Mitre link : CVE-2012-5478
CVE.ORG link : CVE-2012-5478
JSON object : View
Products Affected
                redhat
- jboss_enterprise_web_platform
- jboss_enterprise_brms_platform
- jboss_enterprise_application_platform
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
