VulnerabilityModified
CVE-2013-4373
The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load arbitrary drift files into a server by writing the files to the temporary directory that is used to unpack zip files.
LOW 3.2EPSS 0.30%
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load arbitrary drift files into a server by writing the files to the temporary directory that is used to unpack zip files.
- CVSS 2.0
- 3.2 LOWAV:L/AC:L/Au:S/C:N/I:P/A:P
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- redhat/jboss operations network
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2013-1448.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1011824Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88179
- http://rhn.redhat.com/errata/RHSA-2013-1448.htmlVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1011824Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/88179
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.