PT-2013-4981 · Red Hat · Red Hat Jboss Operations Network

Published

2013-10-24

·

Updated

2017-08-29

·

CVE-2013-4373

CVSS v2.0

3.2

Low

VectorAV:L/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Red Hat JBoss Operations Network (JON) version 3.1.2
Description The issue allows local users to load arbitrary drift files into a server. This is achieved by writing the files to the temporary directory used to unpack zip files through the storeFiles method in JPADriftServerBean.
Recommendations For Red Hat JBoss Operations Network (JON) version 3.1.2, consider restricting access to the temporary directory used for unpacking zip files to prevent arbitrary file loading. As a temporary workaround, consider disabling the storeFiles method in JPADriftServerBean until a patch is available.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4373

Affected Products

Red Hat Jboss Operations Network