{"api_version":"1","generated_at":"2026-07-23T09:05:25+00:00","cve":"CVE-2012-4599","urls":{"html":"https://cve.report/CVE-2012-4599","api":"https://cve.report/api/cve/CVE-2012-4599.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-4599","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-4599"},"summary":{"title":"CVE-2012-4599","description":"McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to execute arbitrary code via a crafted .war file.","state":"PUBLISHED","assigner":"mitre","published_at":"2012-08-22 10:42:05","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10029","name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10029","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"McAfee KnowledgeBase - McAfee Security Bulletin - McAfee SmartFilter Administration 4.2.1 and earlier - Unauthenticated access to JBOSS RMI interface","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-4599","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-4599","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"4599","vulnerable":"1","versionEndIncluding":"4.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"smartfilter_administration","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2012","cve_id":"4599","vulnerable":"1","versionEndIncluding":"4.2.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"smartfilter_administration","cpe6":"*","cpe7":"*","cpe8":"bess","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T20:42:54.682Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10029"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-05-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to execute arbitrary code via a crafted .war file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2012-08-24T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10029"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2012-4599","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to execute arbitrary code via a crafted .war file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10029","refsource":"CONFIRM","url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10029"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2012-4599","datePublished":"2012-08-22T10:00:00.000Z","dateReserved":"2012-08-22T00:00:00.000Z","dateUpdated":"2024-08-06T20:42:54.682Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-08-22 10:42:05","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mcafee:smartfilter_administration:*:*:*:*:*:*:*:*","versionEndIncluding":"4.2.1","matchCriteriaId":"39E48E7D-BB4E-4CF4-BA56-A7B41FDB274A"},{"vulnerable":true,"criteria":"cpe:2.3:a:mcafee:smartfilter_administration:*:*:bess:*:*:*:*:*","versionEndIncluding":"4.2.1","matchCriteriaId":"0AC5A81D-5D22-4ABD-A4F0-62BF709C330A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"4599","Ordinal":"1","Title":"CVE-2012-4599","CVE":"CVE-2012-4599","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"4599","Ordinal":"1","NoteData":"McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to execute arbitrary code via a crafted .war file.","Type":"Description","Title":"CVE-2012-4599"},{"CveYear":"2012","CveId":"4599","Ordinal":"2","NoteData":"2012-08-22","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"4599","Ordinal":"3","NoteData":"2012-08-24","Type":"Other","Title":"Modified"}]}}}