Vulnerable Systems:
*Red Hat, Inc. JBoss Enterprise Application Platform 5.1.9
* Red Hat, Inc. JBoss Enterprise Web Platform 5.1.9
JBoss Enterprise Application Platform and JBoss Enterprise Web Platform contain a flaw that is due to CallerIdentityLoginModule retaining passwords from a previous call if a null password is provided. This will cause the program to load a session with credentials that have been retained from the previous call, which will allow a remote attacker to more easily hijack a user's session.