PT-2018-3344 · Red Hat+1 · Jboss Administration+1

Published

2018-12-19

·

Updated

2019-05-23

·

CVE-2018-6443

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Brocade Network Advisor versions prior to 14.3.1
Description: A vulnerability in Brocade Network Advisor could allow an unauthenticated, remote attacker to log in to the JBoss Administration interface of an affected system using undocumented user credentials and install additional JEE applications. This issue is related to inadequate storage of credentials. An attacker with access to Network Advisor client libraries and the ability to decrypt the JBoss credentials could gain access to the JBoss web console, potentially leading to unauthorized access to protected information through the JMX console.
Recommendations: For versions prior to 14.3.1, update to version 14.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the JBoss Administration interface and limiting the use of Network Advisor client libraries to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00133
CVE-2018-6443

Affected Products

Brocade Network Advisor
Jboss Administration