PT-2013-3542 · Red Hat · Red Hat Jboss Portal

Publicado

2013-10-28

·

Atualizado

2013-10-30

·

CVE-2013-2102

CVSS v2.0

3.3

Baixa

VetorAV:A/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Portal versions prior to 6.1.0
Description The default configuration of Red Hat JBoss Portal enables the JGroups diagnostics service with no authentication when a JGroups channel is started. This allows remote attackers to obtain sensitive information by accessing the service.
Recommendations For versions prior to 6.1.0, update to version 6.1.0 or later to resolve the issue. As a temporary workaround, consider disabling the JGroups diagnostics service until a patch is available. Restrict access to the JGroups channel to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-2102

Produtos afetados

Red Hat Jboss Portal