SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-0052

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agents via the registered agent name.

MEDIUM 5.8EPSS 1.18%

Does this matter?

Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.

Description

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agents via the registered agent name.

CVSS 2.0
5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
EPSS
1.18% probability · 66th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
redhat/jboss operations network
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.