Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4112

Опубликовано: 11 июл. 2013
Источник: redhat
CVSS2: 3.3
EPSS Низкий

Описание

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5jgroupsNot affected
Red Hat JBoss Enterprise Application Platform 5jgroupsNot affected
Red Hat JBoss Operations Network 3jgroupsNot affected
Red Hat JBoss Portal 4jgroupsNot affected
Red Hat JBoss Portal 5jgroupsNot affected
Red Hat JBoss SOA Platform 4jgroupsNot affected
Red Hat JBoss SOA Platform 5jgroupsNot affected
Red Hat JBoss Data Grid 6.2jgroupsFixedRHSA-2014:002915.01.2014
Red Hat JBoss Enterprise Application Platform 6.1jgroupsFixedRHSA-2013:120904.09.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5apache-commons-beanutilsFixedRHSA-2013:120704.09.2013

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=983489JGroups: Authentication via cached credentials

EPSS

Процентиль: 74%
0.01607
Низкий

3.3 Low

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.

nvd
почти 13 лет назад

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and 3.3.x before 3.3.3 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.

debian
почти 13 лет назад

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x before 3.2.9, and ...

github
около 4 лет назад

Exposure of Sensitive Information to an Unauthorized Actor in JGroup

EPSS

Процентиль: 74%
0.01607
Низкий

3.3 Low

CVSS2

Уязвимость CVE-2013-4112