CVE-2012-2377
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent…
Does this matter?
Lower severity and a low EPSS score (1.45%). Track it; it rarely justifies an emergency change on its own.
Description
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.
- CVSS 2.0
- 3.3 LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.45% probability · 72th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- redhat/jboss enterprise portal platform · redhat/jboss enterprise soa platform · redhat/jboss enterprise brms platform
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2012-1028.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1125.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1232.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0191.html
- http://rhn.redhat.com/errata/RHSA-2013-0192.html
- http://rhn.redhat.com/errata/RHSA-2013-0193.html
- http://rhn.redhat.com/errata/RHSA-2013-0194.html
- http://rhn.redhat.com/errata/RHSA-2013-0195.html
- http://rhn.redhat.com/errata/RHSA-2013-0196.html
- http://rhn.redhat.com/errata/RHSA-2013-0197.html
- http://rhn.redhat.com/errata/RHSA-2013-0198.html
- http://secunia.com/advisories/49669Vendor Advisory
- http://secunia.com/advisories/50084Vendor Advisory
- http://secunia.com/advisories/50549Vendor Advisory
- http://secunia.com/advisories/51984
- http://www.osvdb.org/83085
- http://www.securityfocus.com/bid/54183
- https://bugzilla.redhat.com/show_bug.cgi?id=823392
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76540
- http://rhn.redhat.com/errata/RHSA-2012-1028.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1125.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2012-1232.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-0191.html
- http://rhn.redhat.com/errata/RHSA-2013-0192.html
- http://rhn.redhat.com/errata/RHSA-2013-0193.html
- http://rhn.redhat.com/errata/RHSA-2013-0194.html
- http://rhn.redhat.com/errata/RHSA-2013-0195.html
- http://rhn.redhat.com/errata/RHSA-2013-0196.html
- http://rhn.redhat.com/errata/RHSA-2013-0197.html
- http://rhn.redhat.com/errata/RHSA-2013-0198.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.