Back

MEDIUM

Invoker servlets authentication bypass (HTTP verb tampering)

Published Nov 23, 2012

Description

The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method. NOTE: this vulnerability exists because of a CVE-2010-0738 regression.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 23, 2012
Updated Aug 6, 2024
Reserved Oct 18, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Nov 16, 2011