CVE-2012-3428
JBoss: Datasource connection manager returns valid connection for wrong credentials when using security-domains
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers to obtain access to an arbitrary datasource connection in opportunistic circumstances via an invalid connection attempt.
El contenedor IronJacamar antes de v1.0.12.Final para el servidor de aplicaciones JBoss, cuando allow-multiple-users se activa en combinación con un dominio de seguridad, no utiliza las credenciales proporcionadas en una llamada de función getConnection, lo que permite a atacantes remotos obtener acceso a una conexión de fuente de datos arbitraria en circunstancias oportunistas a través de un intento de conexión no válida.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-06-14 CVE Reserved
- 2012-12-19 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-255: Credentials Management Errors
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/51607 | Third Party Advisory | |
https://issues.jboss.org/browse/JBPAPP-9584 | X_refsource_misc | |
https://issues.jboss.org/secure/ReleaseNote.jspa?projectId=12310691&version=12319522 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2012-1591.html | 2013-01-08 | |
http://rhn.redhat.com/errata/RHSA-2012-1592.html | 2013-01-08 | |
http://rhn.redhat.com/errata/RHSA-2012-1594.html | 2013-01-08 | |
https://bugzilla.redhat.com/show_bug.cgi?id=843358 | 2012-12-18 | |
https://issues.jboss.org/browse/JBJCA-864 | 2013-01-08 | |
https://access.redhat.com/security/cve/CVE-2012-3428 | 2012-12-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jboss Search vendor "Jboss" | Ironjacamar Search vendor "Jboss" for product "Ironjacamar" | <= 1.0.11 Search vendor "Jboss" for product "Ironjacamar" and version " <= 1.0.11" | - |
Affected
|