Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-4529

Опубликовано: 28 окт. 2013
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:jboss_community_application_server:*:*:*:*:*:*:*:*
Версия до 7.1.1 (включая)
cpe:2.3:a:redhat:jboss_community_application_server:5.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:5.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:5.1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:6.1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:7.0.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_community_application_server:7.1.0:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01977
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

ubuntu
почти 13 лет назад

The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.

redhat
почти 14 лет назад

The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.

debian
почти 13 лет назад

The org.apache.catalina.connector.Response.encodeURL method in Red Hat ...

github
около 4 лет назад

The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.

EPSS

Процентиль: 79%
0.01977
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-noinfo