1 results (0.004 seconds)
CVSS: 9.1EPSS: 0%CPEs: 1EXPL: 0

CVE-2012-3428 – JBoss: Datasource connection manager returns valid connection for wrong credentials when using security-domains
https://notcve.org/view.php?id=CVE-2012-3428
20 Dec 2012 — The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers to obtain access to an arbitrary datasource connection in opportunistic circumstances via an invalid connection attempt. El contenedor IronJacamar antes de v1.0.12.Final para el servidor de aplicaciones JBoss, cuando allow-multiple-users se activa en combina... • http://rhn.redhat.com/errata/RHSA-2012-1591.html • CWE-255: Credentials Management Errors •