PT-2010-1651 · Red Hat+1 · Jboss+1

Published

2010-05-07

·

Updated

2018-10-10

·

CVE-2009-4843

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ToutVirtual VirtualIQ Pro versions prior to 3.5 build 8691
Description The issue allows remote attackers to execute arbitrary commands due to the lack of administrative authentication for JBoss console access. This can be achieved via requests to the JMX Management Console or the Web Console.
Recommendations For versions prior to 3.5 build 8691, update to version 3.5 build 8691 or later to ensure administrative authentication is required for JBoss console access.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4843

Affected Products

Jboss
Virtualiq Pro