The Access Control functionality (JMXOpsAccessControlFilter) in JMX Console in JBoss Application Server 4.0.2 and 4.0.5 before 20070416 uses a member variable to store the roles of the current user, which allows remote authenticated administrators to trigger a race condition and gain privileges by logging in during a session by a more privileged administrator, as demonstrated by privilege escalation from Read Mode to Write Mode.
2007-07-27T21:30:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 6.0 (MEDIUM)
AV:N/AC:M/Au:S/C:P/I:P/A:P
6.8
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | jboss | jboss_application_server | 4.0.2.ga_cp02 | Yes |
Application | jboss | jboss_application_server | 4.0.2.ga_cp03 | Yes |
Application | jboss | jboss_application_server | 4.0.2.ga_cp04 | Yes |
Application | jboss | jboss_application_server | 4.0.5.ga | Yes |
Application | jboss | jboss_application_server | 4.0.5_cp01 | Yes |
Application | jboss | jboss_application_server | 4.0.5_cp02 | Yes |