Vulnerabilities (CVE)

Filtered by vendor Jboss Subscribe
Filtered by product Enterprise Java Beans
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-4709 1 Jboss 1 Enterprise Java Beans 2023-12-10 5.0 MEDIUM N/A
The popSubjectContext method in the SecurityAssociation class in JBoss Enterprise Java Beans (EJB) 3.0 RC3 maintains the threadPrincipal and threadCredential values from a previous client's authentication after termination of a client session, which allows remote attackers to gain the roles of an arbitrary previous client who had the same JBoss server thread.