Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-4572

EPSS 0.15% · P36
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2012-4572

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Red Hat JBoss JBoss EAP 身份验证安全绕过漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Red Hat JBoss Enterprise Application Platform(EAP)和JBoss Portal都是美国红帽(Red Hat)公司的产品。JBoss EAP是一套开源、基于J2EE的中间件平台。JBoss Portal是一套开源且符合标准的门户平台。 Red Hat JBoss EAP 6.1.0之前的版本和JBoss Portal 6.1.0之前的版本中存在安全漏洞,该漏洞源于程序没有正确加载新应用程序的用户身份验证模块。本地攻击者可借助特制的应用程序利用该漏洞控制应用程序
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2012-4572

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2012-4572

登录查看更多情报信息。

Same Patch Batch · n/a · 2013-10-28 · 28 CVEs total

CVE-2013-4402GnuPG 拒绝服务漏洞
CVE-2013-6285Tyler Technologies TaxWeb 信息泄露漏洞
CVE-2013-6020Tyler Technologies TaxWeb 信息泄露漏洞
CVE-2013-6019Tyler Technologies TaxWeb 跨站脚本漏洞
CVE-2013-6018Tyler Technologies TaxWeb 跨站请求伪造漏洞
CVE-2013-5430IBM Security AppScan Enterprise Jazz Team Server组件信任管理漏洞
CVE-2013-2186Apache Commons FileUpload 输入验证错误漏洞
CVE-2013-2102Red Hat JBoss Portal JGroups Diagnostics Service 信息泄露漏洞
CVE-2013-1056X.Org X Server Xephyr 本地拒绝服务漏洞
CVE-2012-4529Red Hat JBoss Web 会话ID信息泄露漏洞
CVE-2013-6289TYPO3 Apache Solr for TYPO3扩展跨站脚本漏洞
CVE-2013-6288TYPO3 Apache Solr for TYPO3扩展安全漏洞
CVE-2013-6012Juniper Junos 未授权访问漏洞
CVE-2013-5744Feng Office ‘index.php’ 跨站脚本漏洞
CVE-2013-6014Juniper Junos 信息泄露漏洞
CVE-2013-4394systemd X Keyboard Extension Processing 本地提权漏洞
CVE-2013-4393systemd ‘journald’功能拒绝服务漏洞
CVE-2013-4392systemd 后置链接漏洞
CVE-2013-4391systemd ‘journald-native.c’远程整数溢出漏洞
CVE-2013-3704libzypp RPM GPG密钥导入和处理功能安全漏洞

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2012-4572

No comments yet


Leave a comment