Vulnerability Details CVE-2012-2312
An Elevated Privileges issue exists in JBoss AS 7 Community Release due to the improper implementation in the security context propagation, A threat gets reused from the thread pool that still retains the security context from the process last used, which lets a local user obtain elevated privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.9%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 4.6
Products affected by CVE-2012-2312
-
cpe:2.3:a:redhat:jboss_application_server:7.1.0
-
cpe:2.3:a:redhat:jboss_application_server:7.1.1
-
cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0