Filtered by vendor Jboss Subscriptions
Filtered by product Enterprise Java Beans Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2005-4709 1 Jboss 1 Enterprise Java Beans 2024-11-21 N/A
The popSubjectContext method in the SecurityAssociation class in JBoss Enterprise Java Beans (EJB) 3.0 RC3 maintains the threadPrincipal and threadCredential values from a previous client's authentication after termination of a client session, which allows remote attackers to gain the roles of an arbitrary previous client who had the same JBoss server thread.