CVE-2013-4572
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2013-4572 affects Red Hat JBoss Enterprise Application Platform (EAP) before version 6.1.0 and JBoss Portal before 6.1.0. The vulnerability was discovered by Josef Cacek of the Red Hat JBoss EAP Quality Engineering team and was disclosed in May 2013 (Red Hat Advisory).

Technical details

The vulnerability occurs when multiple applications use the same custom authorization module class name and provide their own implementations. In this scenario, the first application to be loaded will have its implementation used for all other applications using the same custom authorization module class name. The vulnerability has a CVSS v2.0 base score of 3.7 (LOW) with vector (AV:L/AC:H/Au:N/C:P/I:P/A:P) (NVD).

Impact

The vulnerability allows local attackers to control certain applications' authorization decisions by deploying a malicious application that provides implementations of custom authorization modules that permit or deny user access according to rules supplied by the attacker (Red Hat Advisory).

Mitigation and workarounds

Red Hat released security updates to address this vulnerability in JBoss Enterprise Application Platform 6.1.0. Users of affected versions are advised to upgrade to the fixed version. Before applying the update, users should back up their existing JBoss Enterprise Application Platform installation and deployed applications (Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-0821MEDIUM6.9
  • Linux DebianLinux Debian
  • quickjs
NoNoJan 10, 2026
CVE-2026-22703MEDIUM5.5
  • Linux DebianLinux Debian
  • cosign
NoNoJan 10, 2026
CVE-2026-0822MEDIUM5.3
  • Linux DebianLinux Debian
  • quickjs
NoNoJan 10, 2026
CVE-2025-15506MEDIUM4.8
  • Linux DebianLinux Debian
  • opencolorio
NoNoJan 11, 2026
CVE-2026-22702MEDIUM4.5
  • Linux DebianLinux Debian
  • python-virtualenv
NoNoJan 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management