The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.
Advisories
Source ID Title
EUVD EUVD EUVD-2012-4477 The processInvocation function in org.jboss.as.ejb3.security.AuthorizationInterceptor in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, authorizes all requests when no roles are allowed for an Enterprise Java Beans (EJB) method invocation, which allows attackers to bypass intended access restrictions for EJB methods.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T20:42:54.149Z

Reserved: 2012-08-21T00:00:00Z

Link: CVE-2012-4549

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2013-01-05T00:55:02.947

Modified: 2025-04-11T00:51:21.963

Link: CVE-2012-4549

cve-icon Redhat

Severity : Moderate

Publid Date: 2012-12-18T00:00:00Z

Links: CVE-2012-4549 - Bugzilla

cve-icon OpenCVE Enrichment

No data.