Vulnerable Systems:
*Red Hat, Inc. JBoss Enterprise Application Platform 5.1.9
* Red Hat, Inc. JBoss Enterprise Web Platform 5.1.9
JBoss Enterprise Application Platform and JBoss Enterprise Web Platform contain a flaw that is due to the JMXInvokerHAServlet and EJBInvokerHAServlet invoker servlets not properly restricting access to profiles. This may allow a remote attacker to bypass authentication and view arbitrary user's profiles.