Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-2141

Опубликовано: 23 июн. 2016
Источник: redhat
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.

Меры по смягчению последствий

Please refer to https://access.redhat.com/articles/2360521 for more information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7JGroupsNot affected
Red Hat BPM Suite 6ClusteringAffected
Red Hat Enterprise Virtualization 3distributionNot affected
Red Hat Fuse 7camelNot affected
Red Hat JBoss BRMS 6ClusteringAffected
Red Hat JBoss Fuse 6camelAffected
Red Hat Single Sign-On 7ClusteringAffected
JBoss Enterprise BRMS Platform 5.3ClusteringFixedRHSA-2016:134527.06.2016
Red Hat JBoss BRMS 6.3ClusteringFixedRHSA-2016:134527.06.2016
Red Hat JBoss BRMS 6.3ClusteringFixedRHSA-2016:134727.06.2016

Показывать по

Дополнительная информация

Статус:

Critical

EPSS

Процентиль: 85%
0.02357
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 9 лет назад

It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.

CVSS3: 9.8
nvd
больше 9 лет назад

It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.

CVSS3: 9.8
debian
больше 9 лет назад

It was found that JGroups did not require necessary headers for encryp ...

CVSS3: 9.8
github
больше 3 лет назад

Improper Input Validation in JGroups

EPSS

Процентиль: 85%
0.02357
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Уязвимость CVE-2016-2141