Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-0874

Опубликовано: 24 янв. 2013
Источник: redhat
CVSS2: 2.6
EPSS Средний

Описание

The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5SecurityNot affected
Red Hat JBoss Portal 4RequirementsAffected
Red Hat JBoss Portal 5RequirementsWill not fix
Red Hat JBoss SOA Platform 5SecurityAffected
JBEWP 5 for RHEL 5aopallianceFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5apache-cxfFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5bsh2FixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5glassfish-jaxbFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5google-guiceFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5hibernate3FixedRHSA-2013:019624.01.2013

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=795645JBoss invoker servlets do not require authentication

EPSS

Процентиль: 98%
0.5129
Средний

2.6 Low

CVSS2

Связанные уязвимости

nvd
около 13 лет назад

The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.

debian
около 13 лет назад

The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servle ...

github
больше 3 лет назад

The (1) JMXInvokerHAServlet and (2) EJBInvokerHAServlet invoker servlets in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 do not require authentication by default in certain profiles, which might allow remote attackers to invoke MBean methods and execute arbitrary code via unspecified vectors. NOTE: this issue can only be exploited when the interceptor is not properly configured with a "second layer of authentication," or when used in conjunction with other vulnerabilities that bypass this second layer.

EPSS

Процентиль: 98%
0.5129
Средний

2.6 Low

CVSS2

Уязвимость CVE-2012-0874