JBoss ESB Domain Validation Remote Privilege Escalation Vulnerability
BID:41915
Info
JBoss ESB Domain Validation Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 41915 |
| Class: | Access Validation Error |
| CVE: |
CVE-2010-2474 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2010 12:00AM |
| Updated: | Jul 23 2010 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
JBoss Group JBoss ESB 4.7 CP1 |
| Not Vulnerable: |
JBoss Group JBoss ESB 4.7 CP2 |
Discussion
JBoss ESB Domain Validation Remote Privilege Escalation Vulnerability
JBoss ESB is prone to an remote privilege-escalation vulnerability because it fails to properly validate the security context in authentication requests.
Authenticated attackers can exploit this issue to gain elevated privileges on the affected computer.
JBoss ESB is prone to an remote privilege-escalation vulnerability because it fails to properly validate the security context in authentication requests.
Authenticated attackers can exploit this issue to gain elevated privileges on the affected computer.
Exploit / POC
JBoss ESB Domain Validation Remote Privilege Escalation Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
JBoss ESB Domain Validation Remote Privilege Escalation Vulnerability
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
JBoss ESB Domain Validation Remote Privilege Escalation Vulnerability
References:
References:
- JBoss ESB Homepage (JBoss)
- Security context should contain domain information (JBoss)