SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-2377

JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent…

LOW 3.3EPSS 1.45%

Does this matter?

Lower severity and a low EPSS score (1.45%). Track it; it rarely justifies an emergency change on its own.

Description

JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.

CVSS 2.0
3.3 LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
EPSS
1.45% probability · 72th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
redhat/jboss enterprise portal platform · redhat/jboss enterprise soa platform · redhat/jboss enterprise brms platform
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.