CVE-2012-4550
medium
📛 Threat Title
CVE-2012-4550
Description
A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (9)
- secalert@redhat.com NVD Recent CVEs
- secalert@redhat.com NVD Recent CVEs
- secalert@redhat.com NVD Recent CVEs
- secalert@redhat.com NVD Recent CVEs
- secalert@redhat.com NVD Recent CVEs
- secalert@redhat.com NVD Recent CVEs
- secalert@redhat.com NVD Recent CVEs
- secalert@redhat.com NVD Recent CVEs
-
NVD detail: CVE-2012-4550
NVD Recent CVEs
A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs.
Remediations (8)
-
web:cheatsheetseries.owasp.org
Minimize Time-to- Fix - Fixing application source code takes time. The main purpose of a virtual patch is to implement a mitigation for the identified vulnerability as soon as possible.
-
web:docs.tenable.com
Mitigation Verify Mitigation Frequently, vulnerabilities targeted for remediation are never fully remediated. While security teams are responsible for detecting and prioritizing vulnerabilities, patching the vulnerabilities is the responsibility of IT staff and developers who speak a different language and have different goals.
-
web:support.servicenow.com
Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...
-
web:www.cisa.gov
Patches are software and operating system (OS) updates that address security vulnerabilities within a program or product. Software vendors may choose to release updates to fix performance bugs, as well as to provide enhanced security features.
-
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
-
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
-
web:www.secure.com
Remediation fully removes a vulnerability by fixing its root cause — through a patch , code fix , or system replacement. Mitigation reduces the risk of exploitation without removing the flaw itself, using controls like network segmentation or access restrictions.
-
web:www.securityweek.com
F5's May 2026 quarterly security notification details 51 high and medium-severity vulnerabilities impacting BIG-IP, BIG-IQ, and NGINX.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.