Bug 843358 (CVE-2012-3428) - CVE-2012-3428 JBoss: Datasource connection manager returns valid connection for wrong credentials when using security-domains
Summary: CVE-2012-3428 JBoss: Datasource connection manager returns valid connection f...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-3428
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 843362 888625
Blocks: 843361 881519
TreeView+ depends on / blocked
 
Reported: 2012-07-26 06:37 UTC by Arun Babu Neelicattu
Modified: 2023-05-12 23:13 UTC (History)
6 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-01-02 03:46:46 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker JBPAPP-9584 0 Critical Closed CVE-2012-3428: <allow-multiple-users/> doesn't take effect when using a security domain 2017-01-26 13:17:29 UTC
Red Hat Product Errata RHSA-2012:1591 0 normal SHIPPED_LIVE Important: JBoss Enterprise Application Platform 6.0.1 update 2012-12-19 03:19:29 UTC
Red Hat Product Errata RHSA-2012:1592 0 normal SHIPPED_LIVE Important: JBoss Enterprise Application Platform 6.0.1 update 2012-12-19 03:31:01 UTC
Red Hat Product Errata RHSA-2012:1594 0 normal SHIPPED_LIVE Important: JBoss Enterprise Application Platform 6.0.1 update 2012-12-19 03:52:56 UTC

Description Arun Babu Neelicattu 2012-07-26 06:37:26 UTC
When using multi-user authentication provided by the "allow-multiple-users" option for the datasource's connection pool together with a security domain, the credentials provided as arguments to the getConnection(uid,pwd) function are ignored. This means that a valid connection will be returned for an invalid credential. 

This could also mean that, provided the correct subject, a datasource connection can be obtained that which might belong to a privileged user.

A fix for this issue is already available up-stream. The up-stream fix is located at [jira JBJCA-864].

Comment 9 Murray McAllister 2012-10-10 06:06:47 UTC
Acknowledgements:

This issue was discovered by Arun Neelicattu of the Red Hat Security Response Team.

Comment 10 errata-xmlrpc 2012-12-18 22:21:38 UTC
This issue has been addressed in following products:

  JBEAP 6 for RHEL 5

Via RHSA-2012:1591 https://rhn.redhat.com/errata/RHSA-2012-1591.html

Comment 11 errata-xmlrpc 2012-12-18 22:33:31 UTC
This issue has been addressed in following products:

  JBEAP 6 for RHEL 6

Via RHSA-2012:1592 https://rhn.redhat.com/errata/RHSA-2012-1592.html

Comment 12 errata-xmlrpc 2012-12-18 22:53:26 UTC
This issue has been addressed in following products:

  JBoss Enterprise Application Platform 6.0.1

Via RHSA-2012:1594 https://rhn.redhat.com/errata/RHSA-2012-1594.html


Note You need to log in before you can comment on or make changes to this bug.