Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2012-2377

Опубликовано: 12 июн. 2012
Источник: redhat
CVSS2: 3.3
EPSS Низкий

Описание

JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5SecurityAffected
Red Hat JBoss Enterprise Web Server 1unknownUnder investigation
Red Hat JBoss Portal 5RequirementsAffected
Red Hat JBoss SOA Platform 5SecurityAffected
JBEWP 5 for RHEL 5aopallianceFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5apache-cxfFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5bsh2FixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5glassfish-jaxbFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5google-guiceFixedRHSA-2013:019624.01.2013
JBEWP 5 for RHEL 5hibernate3FixedRHSA-2013:019624.01.2013

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=823392JGroups diagnostics service enabled by default with no authentication when a JGroups channel is started

EPSS

Процентиль: 76%
0.00989
Низкий

3.3 Low

CVSS2

Связанные уязвимости

ubuntu
около 13 лет назад

JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.

nvd
около 13 лет назад

JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.

debian
около 13 лет назад

JGroups diagnostics service in JBoss Enterprise Portal Platform before ...

github
больше 3 лет назад

JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.

EPSS

Процентиль: 76%
0.00989
Низкий

3.3 Low

CVSS2

Уязвимость CVE-2012-2377