Looking for the vulnerability index of Invicti's legacy products?
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3369) - Vulnerability Database

Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3369)

Description

The CallerIdentityLoginModule in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to gain privileges of the previous user via a null password, which causes the previous user's password to be used.

References

Related Vulnerabilities