Red Hat Enterprise MRG Messaging and Grid Security Bypass Vulnerability
BID:49500
Info
Red Hat Enterprise MRG Messaging and Grid Security Bypass Vulnerability
| Bugtraq ID: | 49500 |
| Class: | Design Error |
| CVE: |
CVE-2011-2925 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 07 2011 12:00AM |
| Updated: | Apr 13 2015 09:01PM |
| Credit: | Reported in a Red Hat Linux security advisory |
| Vulnerable: |
Redhat MRG Management RHEL 5 Server |
| Not Vulnerable: | |
Discussion
Red Hat Enterprise MRG Messaging and Grid Security Bypass Vulnerability
Red Hat Enterprise MRG Messaging and Grid are prone to a security-bypass vulnerability.
Local attackers can exploit this issue to publish to a broker outside of the Cumin's control and perform certain operations such as scheduling jobs, setting attributes on jobs, as well as holding, releasing or removing job.
Red Hat Enterprise MRG Messaging and Grid are prone to a security-bypass vulnerability.
Local attackers can exploit this issue to publish to a broker outside of the Cumin's control and perform certain operations such as scheduling jobs, setting attributes on jobs, as well as holding, releasing or removing job.
Exploit / POC
Red Hat Enterprise MRG Messaging and Grid Security Bypass Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Red Hat Enterprise MRG Messaging and Grid Security Bypass Vulnerability
Solution:
Vendor patch is available. Please see the references for more information.
Solution:
Vendor patch is available. Please see the references for more information.
References
Red Hat Enterprise MRG Messaging and Grid Security Bypass Vulnerability
References:
References:
- Red Hat Homepage (Red Hat)