JBoss AS Administration Cross Site Request Forgery Vulnerability
BID:50888
CVE-2011-3609 |Info
JBoss AS Administration Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 50888 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-3609 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 02 2011 12:00AM |
| Updated: | Dec 02 2011 12:00AM |
| Credit: | David Black |
| Vulnerable: |
Red Hat JBoss Application Server 7.02 Red Hat JBoss Application Server 7.0 |
| Not Vulnerable: | |
Discussion
JBoss AS Administration Cross Site Request Forgery Vulnerability
JBoss AS is prone to a cross-site request-forgery vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
JBoss AS 7.02 is vulnerable; other versions may also be affected.
JBoss AS is prone to a cross-site request-forgery vulnerability.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks.
JBoss AS 7.02 is vulnerable; other versions may also be affected.
Exploit / POC
JBoss AS Administration Cross Site Request Forgery Vulnerability
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI or visit a malicious website.
To exploit these issues, an attacker must entice an unsuspecting victim to follow a malicious URI or visit a malicious website.
Solution / Fix
JBoss AS Administration Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
JBoss AS Administration Cross Site Request Forgery Vulnerability
References:
References: