VulnerabilityModified
CVE-2012-0052
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agents via the registered agent name.
MEDIUM 5.8EPSS 1.18%
Does this matter?
Lower severity and a low EPSS score (1.18%). Track it; it rarely justifies an emergency change on its own.
Description
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agents via the registered agent name.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
- EPSS
- 1.18% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- redhat/jboss operations network
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2012-0089.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0406.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=781964
- http://rhn.redhat.com/errata/RHSA-2012-0089.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-0406.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=781964
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.