VulnerabilityModified
CVE-2013-4213
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
MEDIUM 6.4EPSS 2.47%
Does this matter?
Lower severity and a low EPSS score (2.47%). Track it; it rarely justifies an emergency change on its own.
Description
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 2.47% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- redhat/jboss enterprise application platform
- Source
- secalert@redhat.com
References
- http://osvdb.org/96216
- http://rhn.redhat.com/errata/RHSA-2013-1151.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1152.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1437.htmlVendor Advisory
- http://secunia.com/advisories/54508
- http://www.securitytracker.com/id/1028898Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=985359Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86387
- http://osvdb.org/96216
- http://rhn.redhat.com/errata/RHSA-2013-1151.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1152.htmlVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2013-1437.htmlVendor Advisory
- http://secunia.com/advisories/54508
- http://www.securitytracker.com/id/1028898Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=985359Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86387
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.