Loading...
Loading...
The IronJacamar container before 1.0.12.Final for JBoss Application Server, when allow-multiple-users is enabled in conjunction with a security domain, does not use the credentials supplied in a getConnection function call, which allows remote attackers to obtain access to an arbitrary datasource connection in opportunistic circumstances via an invalid connection attempt.
December 20, 2012
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2012-3428
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.