JBoss Enterprise Application Platform (aka JBoss EAP or...
Moderate severity
Unreviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated May 15, 2026
Description
Published by the National Vulnerability Database
Jan 5, 2013
Published to the GitHub Advisory Database
May 17, 2022
Last updated
May 15, 2026
JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) before 6.0.1, when using role-based authorization for Enterprise Java Beans (EJB) access, does not call the intended authorization modules, which prevents JACC permissions from being applied and allows remote attackers to obtain access to the EJB.
References