PT-2010-1651 · Red Hat+1 · Jboss+1
Publicado
2010-05-07
·
Atualizado
2018-10-10
·
CVE-2009-4843
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ToutVirtual VirtualIQ Pro versions prior to 3.5 build 8691
Description
The issue allows remote attackers to execute arbitrary commands due to the lack of administrative authentication for JBoss console access. This can be achieved via requests to the JMX Management Console or the Web Console.
Recommendations
For versions prior to 3.5 build 8691, update to version 3.5 build 8691 or later to ensure administrative authentication is required for JBoss console access.
Exploit
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jboss
Virtualiq Pro