Описание
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Data Grid 6 | remote-naming | Not affected | ||
| Red Hat JBoss Enterprise Web Server 1 | others | Not affected | ||
| Red Hat JBoss Portal 6 | remote-naming | Affected | ||
| Red Hat JBoss Enterprise Application Platform 6.1 | Fixed | RHSA-2013:1152 | 12.08.2013 | |
| Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 | jboss-as-client-all | Fixed | RHSA-2013:1151 | 12.08.2013 |
| Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 | jboss-ejb-client | Fixed | RHSA-2013:1151 | 12.08.2013 |
| Red Hat JBoss Enterprise Application Platform 6 for RHEL 5 | jboss-remote-naming | Fixed | RHSA-2013:1151 | 12.08.2013 |
| Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 | jboss-as-client-all | Fixed | RHSA-2013:1151 | 12.08.2013 |
| Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 | jboss-ejb-client | Fixed | RHSA-2013:1151 | 12.08.2013 |
| Red Hat JBoss Enterprise Application Platform 6 for RHEL 6 | jboss-remote-naming | Fixed | RHSA-2013:1151 | 12.08.2013 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.4 Medium
CVSS2
Связанные уязвимости
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not pro ...
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.
EPSS
6.4 Medium
CVSS2