JBoss Enterprise Application Platform Multiple Vulnerabilities
BID:37276
Info
JBoss Enterprise Application Platform Multiple Vulnerabilities
| Bugtraq ID: | 37276 |
| Class: | Unknown |
| CVE: |
CVE-2009-1380 CVE-2009-2405 CVE-2009-3554 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 10 2009 12:00AM |
| Updated: | Jul 26 2013 01:24PM |
| Credit: | Swatej Kumar and the vendor. |
| Vulnerable: |
Red Hat JBoss Enterprise Application Platform 4.3 EL5 Red Hat JBoss Enterprise Application Platform 4.3 EL4 Red Hat JBoss Enterprise Application Platform 4.3 Red Hat JBoss Enterprise Application Platform 4.2 EL5 Red Hat JBoss Enterprise Application Platform 4.2 EL4 Red Hat JBoss Enterprise Application Platform 4.2 HP Network Node Manager i 9.10 HP Network Node Manager i 9.0 |
| Not Vulnerable: | |
Discussion
JBoss Enterprise Application Platform Multiple Vulnerabilities
JBoss Enterprise Application Platform is prone to multiple cross-site scripting vulnerabilities and a local information-disclosure vulnerability.
An attacker can exploit these issues to obtain sensitive information or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
JBoss Enterprise Application Platform is prone to multiple cross-site scripting vulnerabilities and a local information-disclosure vulnerability.
An attacker can exploit these issues to obtain sensitive information or to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Exploit / POC
JBoss Enterprise Application Platform Multiple Vulnerabilities
An attacker may use readily available tools to exploit these issues. For a cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
An attacker may use readily available tools to exploit these issues. For a cross-site scripting issue, the attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
JBoss Enterprise Application Platform Multiple Vulnerabilities
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
JBoss Enterprise Application Platform Multiple Vulnerabilities
References:
References:
- JBoss Community Homepage (JBoss Group)