JBoss 'mod_cluster' CVE-2012-1154 Security Bypass Vulnerability
BID:54086
Info
JBoss 'mod_cluster' CVE-2012-1154 Security Bypass Vulnerability
| Bugtraq ID: | 54086 |
| Class: | Access Validation Error |
| CVE: |
CVE-2012-1154 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2012 12:00AM |
| Updated: | Aug 13 2012 10:30PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Red Hat JBoss Enterprise Web Server for Windows 1.0.2 Red Hat JBoss Enterprise Web Server for RHEL 6 1.0.2 Red Hat JBoss Enterprise Web Server for RHEL 6 1.0 Red Hat JBoss Enterprise Web Server for RHEL 5 Server 1.0 Red Hat JBoss Enterprise Web Server for RHEL 4 ES 1.0.2 Red Hat JBoss Communications Platform 5.1.2 |
| Not Vulnerable: | |
Discussion
JBoss 'mod_cluster' CVE-2012-1154 Security Bypass Vulnerability
The JBoss 'mod_cluster' module is prone to a remote security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and to perform unauthorized actions.
The JBoss 'mod_cluster' module is prone to a remote security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and to perform unauthorized actions.
Exploit / POC
JBoss 'mod_cluster' CVE-2012-1154 Security Bypass Vulnerability
Currently we are not not aware of any publicly available exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Currently we are not not aware of any publicly available exploits. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution / Fix
JBoss 'mod_cluster' CVE-2012-1154 Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
JBoss 'mod_cluster' CVE-2012-1154 Security Bypass Vulnerability
References:
References:
- Bug 802200 - (CVE-2012-1154) CVE-2012-1154 mod_cluster registers and exposes the (Red Hat)
- JBoss Community Homepage (JBoss Group)
- RHSA-2012-1010-1 Moderate: mod_cluster security update (Red Hat)
- RHSA-2012-1052-1 Moderate: mod_cluster security update (Red Hat)
- RHSA-2012-1053-1 Moderate: mod_cluster security update (Red Hat)
- RHSA-2012:1011-1 Moderate: mod_cluster security update (Red Hat)
- RHSA-2012:1012-1 Moderate: mod_cluster security update (Red Hat)