PT-2012-4102 · Red Hat+1 · Jboss Application Server+1

David Elze

·

Publicado

2012-05-21

·

Atualizado

2013-05-25

·

CVE-2012-2561

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HP Business Service Management (BSM) version 9.12
Description The issue allows remote attackers to execute arbitrary JSP code within the JBOSS Application Server component. This is achieved by uploading crafted .war files due to improper restrictions. The attack can be performed via a crafted request to TCP port 1098, 1099, or 4444.
Recommendations For HP Business Service Management (BSM) version 9.12, restrict the uploading of .war files to prevent remote attackers from executing arbitrary JSP code. As a temporary workaround, consider restricting access to TCP ports 1098, 1099, and 4444 to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-2561

Produtos afetados

Hp Business Service Management
Jboss Application Server