A flaw was discovered in the way connections for remote EJB invocations via the remote-naming project were cached on the server. A remote attacker could exploit this flaw by using an EJB client to get a previously authenticated connection.
Acknowledgements: This issue was discovered by Wolf-Dieter Fink of the Red Hat GSS Team.
This issue has been addressed in following products: Red Hat JBoss Enterprise Application Platform 6.1.0 Via RHSA-2013:1152 https://rhn.redhat.com/errata/RHSA-2013-1152.html
This issue has been addressed in following products: JBEAP 6 for RHEL 5 JBEAP 6 for RHEL 6 Via RHSA-2013:1151 https://rhn.redhat.com/errata/RHSA-2013-1151.html
This issue has been addressed in following products: Red Hat JBoss Portal 6.1.0 Via RHSA-2013:1437 https://rhn.redhat.com/errata/RHSA-2013-1437.html