CVE-2012-2377

JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.3 UNKNOWN
ADJACENT_NETWORK
LOW
AV:A/AC:L/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
redhatjboss_enterprise_portal_platform
𝑥
≤ 5.2.1
redhatjboss_enterprise_portal_platform
4.3.0
redhatjboss_enterprise_portal_platform
4.3.0:cp07
redhatjboss_enterprise_portal_platform
5.0.0
redhatjboss_enterprise_portal_platform
5.0.1
redhatjboss_enterprise_portal_platform
5.1.0
redhatjboss_enterprise_portal_platform
5.1.1
redhatjboss_enterprise_portal_platform
5.2.0
redhatjboss_enterprise_soa_platform
𝑥
≤ 5.2.0
redhatjboss_enterprise_soa_platform
4.2.0
redhatjboss_enterprise_soa_platform
4.2.0:cp01
redhatjboss_enterprise_soa_platform
4.2.0:cp02
redhatjboss_enterprise_soa_platform
4.2.0:cp03
redhatjboss_enterprise_soa_platform
4.2.0:cp04
redhatjboss_enterprise_soa_platform
4.2.0:cp05
redhatjboss_enterprise_soa_platform
4.2.0:tp02
redhatjboss_enterprise_soa_platform
4.3.0
redhatjboss_enterprise_soa_platform
4.3.0:cp01
redhatjboss_enterprise_soa_platform
4.3.0:cp02
redhatjboss_enterprise_soa_platform
4.3.0:cp03
redhatjboss_enterprise_soa_platform
4.3.0:cp04
redhatjboss_enterprise_soa_platform
4.3.0:cp05
redhatjboss_enterprise_soa_platform
5.0.0
redhatjboss_enterprise_soa_platform
5.0.1
redhatjboss_enterprise_soa_platform
5.0.2
redhatjboss_enterprise_soa_platform
5.1.0
redhatjboss_enterprise_soa_platform
5.1.1
redhatjboss_enterprise_brms_platform
𝑥
≤ 5.2.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jbossas4
precise
not-affected
oneiric
not-affected
natty
not-affected
lucid
not-affected
hardy
not-affected
References