PT-2014-5369 · Red Hat · Red Hat Jboss Soa Platform+3

Publicado

2014-07-22

·

Atualizado

2014-07-23

·

CVE-2014-3518

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Enterprise Application Platform version 5.2.0 Red Hat JBoss BRMS version 5.3.1 Red Hat JBoss Portal Platform version 5.2.2 Red Hat JBoss SOA Platform version 5.3.1
Description The issue is related to the improper implementation of the JSR 160 specification in the jmx-remoting.sar component of JBoss Remoting. This allows remote attackers to execute arbitrary code via unspecified vectors.
Recommendations For Red Hat JBoss Enterprise Application Platform version 5.2.0, update to a version that properly implements the JSR 160 specification. For Red Hat JBoss BRMS version 5.3.1, update to a version that properly implements the JSR 160 specification. For Red Hat JBoss Portal Platform version 5.2.2, update to a version that properly implements the JSR 160 specification. For Red Hat JBoss SOA Platform version 5.3.1, update to a version that properly implements the JSR 160 specification.

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3518

Produtos afetados

Red Hat Jboss Brms
Red Hat Jboss Enterprise Application Platform
Red Hat Jboss Portal Platform
Red Hat Jboss Soa Platform