CVE-2012-4572

UNRATEDCVSS · not yet scored
—
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • No CVSS published and no exploitation signals yet
CISA-KEV: Not listedEPSS PROB: —CVSS v2: —Exploit: None knownExposed services: —

A fix is available — apply it.

Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.

Internet exposure

The internet-exposure footprint is temporarily unavailable — the KEV-Exposure radar's record for this CVE could not be loaded just now. That is not a finding of zero exposed services; please retry shortly.

CVSS v3
—
EchelonGraph score
Not yet assessedEchelonGraph has no severity assessment for this CVE yet. This is not a rating of zero.
EG Score
—
EG Risk
—
EPSS PROB
—
EPSS %ILE
—
KEV
Not listed

Published

October 28, 2013

Last Modified

June 16, 2026

Advisory Details

Enriched advisory details are temporarily unavailable — they could not be loaded just now. That is not a sign that none exist; please retry shortly.

Vendor Advisories for CVE-2012-4572

Vendor advisories for this CVE are temporarily unavailable — the list could not be loaded just now. That is not a sign that none exist; please retry shortly.

Patch Availability(8)

Vendor / EcosystemFix (by version range) / PatchReleasedSource
redhatpatch2013-10-16redhat
redhatpatch2013-05-20redhat
redhatxmltooling-0:1.3.2-10.redhat_4.ep6.el62013-05-20redhat
redhatxmltooling-0:1.3.2-10.redhat_4.ep6.el52013-05-20redhat
redhatRHSA-2013:0833 @ RHSA-2013:0833 — Low (fixes https://access.redhat.com/errata/RHSA-2013:0833)—2013-05-20 00:00:00+00
redhatRHSA-2013:0834 @ RHSA-2013:0834 — Low (fixes https://access.redhat.com/errata/RHSA-2013:0834)—2013-05-20 00:00:00+00
redhatRHSA-2013:0839 @ RHSA-2013:0839 — Low (fixes https://access.redhat.com/errata/RHSA-2013:0839)—2013-05-20 00:00:00+00
redhatRHSA-2013:1437 @ RHSA-2013:1437 — Low (fixes https://access.redhat.com/errata/RHSA-2013:1437)—2013-05-20 00:00:00+00

Patches are aggregated from vendor advisories (Red Hat, Microsoft, Cisco, GitHub) and package ecosystems (OSV, GHSA). Multiple rows for the same upstream release have been deduplicated.

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Frequently asked(3)

What is CVE-2012-4572?
CVE-2012-4572 is a publicly disclosed vulnerability published on October 28, 2013. Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control…
When was CVE-2012-4572 disclosed?
CVE-2012-4572 was first published on October 28, 2013, with the most recent update on June 16, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
How do I remediate CVE-2012-4572?
A fix for CVE-2012-4572 is available: update to the fixed version the vendor names in its advisory.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2012-4572

Explore →

Is Your Infrastructure Affected by CVE-2012-4572?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.