CVE-2011-4085
Summary
| CVE | CVE-2011-4085 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-11-23 20:55:00 UTC |
| Updated | 2023-11-07 02:09:00 UTC |
| Description | The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method. NOTE: this vulnerability exists because of a CVE-2010-0738 regression. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| About Secunia Research | Flexera | SECUNIA | secunia.com | Vendor Advisory |
| RHSA-2012:0091 | REDHAT | rhn.redhat.com | Vendor Advisory |
| Security Advisory SA47866 - Red Hat update for JBoss Enterprise Portal Platform - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | Vendor Advisory |
| access.redhat.com | REDHAT | rhn.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | Vendor Advisory |
| RHSA-2012:1028 | REDHAT | rhn.redhat.com | Vendor Advisory |
| 750422 – (CVE-2011-4085) CVE-2011-4085 Invoker servlets authentication bypass (HTTP verb tampering) | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.