CVE-2012-4572: Red Hat JBoss Enterprise Application Platform

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.

Affected products

  • Red Hat JBoss Enterprise Application Platform: up to and including 6.0.1; version 4.2.0 only; version 4.3.0 only; version 5.0.0 only; version 5.0.1 only; version 5.1.0 only; …
  • Red Hat JBoss Enterprise Portal Platform: up to and including 6.0.0; version 4.3.0 only; version 5.0.0 only; version 5.0.1 only; version 5.1.0 only; version 5.1.1 only; …

Published 2013-10-28. Last modified 2026-06-16.