CVE-2012-0874

Exp

The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.

Published: 2013-02-05 Last update: 2026-04-29 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2012-0874 is rated High Exploit Risk (70.9/100): CVSS Medium severity, with high exploitation likelihood (EPSS 15.56%, 96th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2012-0874

EDB-ID Source Kind Published Link
30211 exploit_db edb 2013-12-11 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2012-0874

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 51.29% 15.56% -35.73%
2 2026-01-22 56.63% 51.29% -5.34%
3 2025-10-28 56.63%

Full EPSS history (15 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2012-0874

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.8 2.0 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:M)
Exploitation needs some favorable conditions, but not exceptional ones.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
8.6 6.4 [email protected]

Weakness enumeration for CVE-2012-0874

OS Trackers for CVE-2012-0874

vendor priority summary link
redhat low https://access.redhat.com/security/cve/CVE-2012-0874

NVD evaluator notes for CVE-2012-0874

Comment: Per http://rhn.redhat.com/errata/RHSA-2013-0192.html "This JBoss Enterprise Application Platform 5.2.0 release serves as a replacement for JBoss Enterprise Application Platform 5.1.2, and includes bug fixes and enhancements." Per http://rhn.redhat.com/errata/RHSA-2013-0196.html "This JBoss Enterprise Web Platform 5.2.0 release serves as a replacement for JBoss Enterprise Web Platform 5.1.2, and includes bug fixes and enhancements."

Affected software / configurations for CVE-2012-0874

Vendor Product Version Raw CPE
redhat jboss_enterprise_application_platform 5.2.0 cpe:2.3:a:redhat:jboss_enterprise_application_platform:5.2.0:*:*:*:*:*:*:*
redhat jboss_enterprise_web_platform 5.2.0 cpe:2.3:a:redhat:jboss_enterprise_web_platform:5.2.0:*:*:*:*:*:*:*
redhat jboss_enterprise_brms_platform <= 5.3.0 cpe:2.3:a:redhat:jboss_enterprise_brms_platform:*:*:*:*:*:*:*:*

References for CVE-2012-0874

URL Tags
http://archives.neohapsis.com/archives/bugtraq/2013-12/0134.html
http://rhn.redhat.com/errata/RHSA-2013-0191.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0192.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0193.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0194.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0195.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0196.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0197.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0198.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0221.html Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0533.html
http://secunia.com/advisories/51984 Vendor Advisory
http://secunia.com/advisories/52054 Vendor Advisory
http://securitytracker.com/id?1028042
http://www.exploit-db.com/exploits/30211
http://www.securityfocus.com/bid/57552
https://bugzilla.redhat.com/show_bug.cgi?id=795645
https://exchange.xforce.ibmcloud.com/vulnerabilities/81511
cvelogic Threat Intelligence