CVE-2012-2377
Summary
| CVE | CVE-2012-2377 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-11-23 20:55:00 UTC |
| Updated | 2017-08-29 01:31:00 UTC |
| Description | JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast. |
Risk And Classification
Problem Types: CWE-287
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 83085 | OSVDB | www.osvdb.org | |
| JBoss Enterprise BRMS Platform JGroups Diagnostics Service Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| RHSA-2012:1125 | REDHAT | rhn.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| Security Advisory SA49669 - Red Hat update for JBoss Enterprise BRMS Platform - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| Security Advisory SA51984 - Red Hat update for JBoss Enterprise Application Platform and JBoss Enterprise Web Platform - Secunia | SECUNIA | secunia.com | |
| 823392 – (CVE-2012-2377) CVE-2012-2377 JGroups diagnostics service enabled by default with no authentication when a JGroups channel is started | MISC | bugzilla.redhat.com | |
| Security Advisory SA50084 - Red Hat update for JBoss Enterprise SOA Platform - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| RHSA-2012:1028 | REDHAT | rhn.redhat.com | Vendor Advisory |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Security Advisory SA50549 - Red Hat update for JBoss Enterprise Portal Platform - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.