CVE-2011-3206
Summary
| CVE | CVE-2011-3206 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-01-08 00:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in the administration interface in RHQ 4.2.0, as used in JBoss Operations Network (aka JON or JBoss ON) before 3.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Jboss Operations Network | 2.0.0 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.0.1 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.1.0 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.2 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.3 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.3.1 | All | All | All |
| Application | Redhat | Jboss Operations Network | 2.4 | All | All | All |
| Application | Redhat | Jboss Operations Network | All | All | All | All |
| Application | Rhq-project | Rhq | 4.2.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JBoss Operations Network Input Validation Flaws Permit Cross-Site Scripting Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Security Advisory SA47197 - RHQ Cross-Site Scripting Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 734662 – (CVE-2011-3206) CVE-2011-3206 JON: Multiple XSS flaws | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| rhn.redhat.com/errata/RHSA-2012-0089.html | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Security Advisory SA47280 - JBoss Operations Network Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.