Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4128

Опубликовано: 11 июл. 2013
Источник: redhat
CVSS2: 6.4

Описание

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 6remote-namingNot affected
Red Hat JBoss Portal 6remote-namingAffected
Red Hat JBoss Enterprise Application Platform 6.1FixedRHSA-2013:115212.08.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5jboss-as-client-allFixedRHSA-2013:115112.08.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5jboss-ejb-clientFixedRHSA-2013:115112.08.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 5jboss-remote-namingFixedRHSA-2013:115112.08.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6jboss-as-client-allFixedRHSA-2013:115112.08.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6jboss-ejb-clientFixedRHSA-2013:115112.08.2013
Red Hat JBoss Enterprise Application Platform 6 for RHEL 6jboss-remote-namingFixedRHSA-2013:115112.08.2013
Red Hat JBoss Portal Platform 6.1FixedRHSA-2013:143716.10.2013

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-384
https://bugzilla.redhat.com/show_bug.cgi?id=984795remote-naming: Session fixation due improper connection caching

6.4 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 13 лет назад

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.

nvd
почти 13 лет назад

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.

debian
почти 13 лет назад

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not pro ...

github
около 4 лет назад

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.

6.4 Medium

CVSS2