Bug 884426 (CVE-2012-5626)

Summary: CVE-2012-5626 JBoss - EJB method invocation ignores roles specified using the @RunAs annotation
Product: [Other] Security Response Reporter: Arun Babu Neelicattu <aneelica>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED WONTFIX QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: anmiller, atangrin, fnasser, grocha, jcacek, jlieskov, mjc, pcheung, security-response-team
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-02-11 01:40:39 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 902170, 902171, 902172, 1070574    
Bug Blocks: 884429, 1049751    

Description Arun Babu Neelicattu 2012-12-06 08:43:10 UTC
When the checkWithPolicy method is called by the EJBJACCPolicyModuleDelegate class during authorization, the current roles are always determined using the caller principal even when a runAs principal exists. As a result, if the @RunAs annotation is used, the current roles will only include those of the caller principal, and those specificed in the @RunAs annotation will be ignored when authorization is performed.

Comment 3 Martin Prpič 2014-01-23 10:55:14 UTC
Acknowledgements:

This issue was discovered by Zbyněk Roubalík of Red Hat.

Comment 9 Arun Babu Neelicattu 2015-02-11 01:40:19 UTC
Statement:

Red Hat JBoss BRMS 5; Red Hat JBoss Enterprise Application Platform 4 and 5; Red Hat JBoss Enterprise Portal Platform 5; Red Hat JBoss Enterprise SOA Platform 4 and 5; and Red Hat JBoss Enterprise Web Platform 5 are now in Phase 3, Extended Life Support, of their respective life cycles. This issue has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat JBoss Middleware and Red Hat JBoss Operations Network Product Update and Support Policy: https://access.redhat.com/support/policy/updates/jboss_notes/