JBoss Enterprise SOA Platform Multiple Security Bypass Vulnerabilities
BID:42022
Info
JBoss Enterprise SOA Platform Multiple Security Bypass Vulnerabilities
| Bugtraq ID: | 42022 |
| Class: | Access Validation Error |
| CVE: |
CVE-2010-2493 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2010 12:00AM |
| Updated: | Jul 15 2010 12:00AM |
| Credit: | Reported by the vendor. |
| Vulnerable: |
JBoss Group JBoss ESB 4.7 CP1 |
| Not Vulnerable: |
JBoss Group JBoss ESB 4.7 CP2 |
Discussion
JBoss Enterprise SOA Platform Multiple Security Bypass Vulnerabilities
JBoss Enterprise SOA Platform is prone to multiple security-bypass vulnerabilities.
Successful exploits can allow attackers to access sensitive information; other attacks may also be possible.
Versions prior to JBoss Enterprise SOA Platform 5.0.2 are affected.
JBoss Enterprise SOA Platform is prone to multiple security-bypass vulnerabilities.
Successful exploits can allow attackers to access sensitive information; other attacks may also be possible.
Versions prior to JBoss Enterprise SOA Platform 5.0.2 are affected.
Exploit / POC
JBoss Enterprise SOA Platform Multiple Security Bypass Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
JBoss Enterprise SOA Platform Multiple Security Bypass Vulnerabilities
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
JBoss Enterprise SOA Platform Multiple Security Bypass Vulnerabilities
References:
References:
- Bug 614774 - (CVE-2010-2493) CVE-2010-2493 JBoss SOA Platform web application au (Marc Schoenefeld )
- JBoss Community Homepage (JBoss Group)
- JBoss Enterprise SOA Platform 5 5.0.2 Release Notes (JBoss)