Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-4529

Опубликовано: 28 окт. 2013
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:jboss_community_application_server:*:*:*:*:*:*:*:*
Версия до 7.1.1 (включая)
cpe:2.3:a:redhat:jboss_community_application_server:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:7.1.0:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 68%
0.00563
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

ubuntu
больше 12 лет назад

The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.

redhat
больше 13 лет назад

The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.

debian
больше 12 лет назад

The org.apache.catalina.connector.Response.encodeURL method in Red Hat ...

github
больше 3 лет назад

The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.

EPSS

Процентиль: 68%
0.00563
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-noinfo