PT-2010-1651 · Red Hat+1 · Jboss+1

Publicado

2010-05-07

·

Atualizado

2018-10-10

·

CVE-2009-4843

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ToutVirtual VirtualIQ Pro versions prior to 3.5 build 8691
Description The issue allows remote attackers to execute arbitrary commands due to the lack of administrative authentication for JBoss console access. This can be achieved via requests to the JMX Management Console or the Web Console.
Recommendations For versions prior to 3.5 build 8691, update to version 3.5 build 8691 or later to ensure administrative authentication is required for JBoss console access.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4843

Produtos afetados

Jboss
Virtualiq Pro