The SecurityAssociation.getCredential method in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 returns the credentials of the previous user when a security context is not provided, which allows remote attackers to gain privileges as other users.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2013-02-05T23:11:00

Updated: 2017-08-28T12:57:01

Reserved: 2012-06-14T00:00:00


Link: CVE-2012-3370

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2013-02-05T23:55:01.490

Modified: 2017-08-29T01:31:54.757


Link: CVE-2012-3370

JSON object: View

cve-icon Redhat Information

No data.

CWE