JBoss Enterprise Application Platform Remote Denial of Service Vulnerability
BID:49654
Info
JBoss Enterprise Application Platform Remote Denial of Service Vulnerability
| Bugtraq ID: | 49654 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2011-1483 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2011 12:00AM |
| Updated: | Jul 26 2013 01:24PM |
| Credit: | Marc Schoenefeld |
| Vulnerable: |
Red Hat JBoss Enterprise Web Platform 5 EL6 Red Hat JBoss Enterprise Web Platform 5 EL5 Red Hat JBoss Enterprise Web Platform 5 EL4 Red Hat JBoss Enterprise Application Platform 4.3 EL5 Red Hat JBoss Enterprise Application Platform 4.3 EL4 Red Hat JBoss Enterprise Application Platform 4.3 Red Hat JBoss Enterprise Application Platform 4.2 EL5 Red Hat JBoss Enterprise Application Platform 4.2 EL4 Red Hat JBoss Enterprise Application Platform 5 EL6 Red Hat JBoss Enterprise Application Platform 5 EL5 Red Hat JBoss Enterprise Application Platform 5 EL4 HP Network Node Manager i 9.10 HP Network Node Manager i 9.0 |
| Not Vulnerable: |
Red Hat JBoss Enterprise Web Platform 5.1.1 Red Hat Jboss Enterprise Soa Platform 5.1.0 Red Hat Jboss Enterprise Soa Platform 4.3.0 Cp05 Red Hat Jboss Enterprise Soa Platform 4.2.0 Cp05 Red Hat JBoss Enterprise Portal Platform 5.1.1 Red Hat JBoss Enterprise Portal Platform 4.3.CP06 Red Hat JBoss Enterprise BRMS Platform 5.1 Red Hat JBoss Enterprise Application Platform 5.1.1 Red Hat JBoss Enterprise Application Platform 4.3.0.CP10 Red Hat JBoss Enterprise Application Platform 4.2.0.CP09 Red Hat JBoss Communications Platform 5.1.1 Red Hat JBoss Communications Platform 1.2.11 |
Discussion
JBoss Enterprise Application Platform Remote Denial of Service Vulnerability
JBoss Enterprise Application Platform is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to cause excessive CPU and memory consumption, denying service to legitimate users.
JBoss Enterprise Application Platform is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to cause excessive CPU and memory consumption, denying service to legitimate users.
Exploit / POC
JBoss Enterprise Application Platform Remote Denial of Service Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
JBoss Enterprise Application Platform Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
JBoss Enterprise Application Platform Remote Denial of Service Vulnerability
References:
References:
- Bug 692584 - (CVE-2011-1483) CVE-2011-1483 JBossWS remote Denial of Service (Red Hat)
- JBoss Enterprise Application Platform Homepage (Red Hat)
- RHSA-2011:1301-1: jbossws-common security update (Red Hat)
- RHSA-2011:1302-1: jbossws-common security update (Red Hat)
- RHSA-2011:1303-1: jbossws-common security update (Red Hat)
- RHSA-2011:1304-1: jbossws-common security update (Red Hat)
- RHSA-2011:1305-1: jbossws security update (Red Hat)
- RHSA-2011:1306-1: jbossws-common security update (Red Hat)
- RHSA-2011:1307-1: jbossws security update (Red Hat)
- RHSA-2011:1308-1: JBoss Communications Platform 1.2.11 and 5.1.1 security update (Red Hat)
- RHSA-2011:1309-1: jbossas security update (Red Hat)
- RHSA-2011:1310-1: jbossws security update (Red Hat)
- RHSA-2011:1311-1: jbossws-common security update (Red Hat)
- RHSA-2011:1312-1: jbossws-common security update (Red Hat)
- RHSA-2011:1313-1: JBoss Enterprise BRMS Platform 5.1.0 security update (Red Hat)