
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2013-4572 affects Red Hat JBoss Enterprise Application Platform (EAP) before version 6.1.0 and JBoss Portal before 6.1.0. The vulnerability was discovered by Josef Cacek of the Red Hat JBoss EAP Quality Engineering team and was disclosed in May 2013 (Red Hat Advisory).
The vulnerability occurs when multiple applications use the same custom authorization module class name and provide their own implementations. In this scenario, the first application to be loaded will have its implementation used for all other applications using the same custom authorization module class name. The vulnerability has a CVSS v2.0 base score of 3.7 (LOW) with vector (AV:L/AC:H/Au:N/C:P/I:P/A:P) (NVD).
The vulnerability allows local attackers to control certain applications' authorization decisions by deploying a malicious application that provides implementations of custom authorization modules that permit or deny user access according to rules supplied by the attacker (Red Hat Advisory).
Red Hat released security updates to address this vulnerability in JBoss Enterprise Application Platform 6.1.0. Users of affected versions are advised to upgrade to the fixed version. Before applying the update, users should back up their existing JBoss Enterprise Application Platform installation and deployed applications (Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."