CVE-2012-4550: Red Hat JBoss Enterprise Application Platform

Medium severity, CVSS 5.3. EPSS: 2.1% chance of exploitation in the next 30 days.

A flaw was found in JBoss Enterprise Application Platform. When role-based authorization is used for Enterprise Java Beans (EJB) access, the system does not correctly call the necessary authorization modules. This prevents Java Authorization Contract for Containers (JACC) permissions from being applied, allowing remote attackers to gain unauthorized access to EJBs.

Affected products

  • Red Hat JBoss Enterprise Application Platform: version 6.0.0 only

Published 2013-01-05. Last modified 2026-06-16.