Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-4112

Опубликовано: 28 сент. 2013
Источник: nvd
CVSS2: 5.4
EPSS Низкий

Описание

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:jgroups:jgroup:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.7:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.8:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.9:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.10:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.11:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.12:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.13:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.0.14:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.2.7:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.2.8:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.3.0:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:jgroups:jgroup:3.3.2:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:redhat:jboss_enterprise_application_platform:6.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 70%
0.00622
Низкий

5.4 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 12 лет назад

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.

redhat
больше 12 лет назад

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.

debian
больше 12 лет назад

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and ...

github
больше 3 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in JGroup

EPSS

Процентиль: 70%
0.00622
Низкий

5.4 Medium

CVSS2

Дефекты

CWE-200