CVE-2009-2405
published 2009-12-15CVE-2009-2405: Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Red Hat JBoss Enterprise Application Platform (aka JBoss…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.53%
83.1th percentile
Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2.0 before 4.2.0.CP08, 4.2.2GA, 4.3 before 4.3.0.CP07, and 5.1.0GA allow remote attackers to inject arbitrary web script or HTML via the (1) monitorName, (2) objectName, (3) attribute, or (4) period parameter to createSnapshot.jsp, or the (5) monitorName, (6) objectName, (7) attribute, (8) threshold, (9) period, or (10) enabled parameter to createThresholdMonitor.jsp. NOTE: some of these details are obtained from third party information.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4q38-x98f-3p77: Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Red Hat JBoss Enterprise Application Platform (aka
ghsa_unreviewed·2022-05-02
CVE-2009-2405 [MEDIUM] CWE-79 GHSA-4q38-x98f-3p77: Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Red Hat JBoss Enterprise Application Platform (aka
Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2.0 before 4.2.0.CP08, 4.2.2GA, 4.3 before 4.3.0.CP07, and 5.1.0GA allow remote attackers to inject arbitrary web script or HTML via the (1) monitorName, (2) objectName, (3) attribute, or (4) period parameter to createSnapshot.jsp, or the (5) monitorName, (6) objectName, (7) attribute, (8) threshold, (9) period, or (10) enabled parameter to createThresholdMonitor.jsp. NOTE: some of these details are obtained from third party information.
Red Hat
JBoss Application Server Web Console XSS
vendor_redhat·2009-07-22·CVSS 4.3
CVE-2009-2405 [MEDIUM] CWE-79 JBoss Application Server Web Console XSS
JBoss Application Server Web Console XSS
Multiple cross-site scripting (XSS) vulnerabilities in the Web Console in the Application Server in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2.0 before 4.2.0.CP08, 4.2.2GA, 4.3 before 4.3.0.CP07, and 5.1.0GA allow remote attackers to inject arbitrary web script or HTML via the (1) monitorName, (2) objectName, (3) attribute, or (4) period parameter to createSnapshot.jsp, or the (5) monitorName, (6) objectName, (7) attribute, (8) threshold, (9) period, or (10) enabled parameter to createThresholdMonitor.jsp. NOTE: some of these details are obtained from third party information.
Statement: This flaw does not affect Red Hat JBoss Enterprise Application Platform 5 or 6. Older versions of the community JBoss Application S
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/35680http://secunia.com/advisories/37671http://securitytracker.com/id?1023315http://www.osvdb.org/60898http://www.osvdb.org/60899http://www.securityfocus.com/bid/37276https://bugzilla.redhat.com/show_bug.cgi?id=510023https://exchange.xforce.ibmcloud.com/vulnerabilities/54700https://jira.jboss.org/jira/browse/JBAS-7105https://jira.jboss.org/jira/browse/JBPAPP-2274https://jira.jboss.org/jira/browse/JBPAPP-2284https://rhn.redhat.com/errata/RHSA-2009-1636.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1637.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1649.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1650.htmlhttp://secunia.com/advisories/35680http://secunia.com/advisories/37671http://securitytracker.com/id?1023315http://www.osvdb.org/60898http://www.osvdb.org/60899http://www.securityfocus.com/bid/37276https://bugzilla.redhat.com/show_bug.cgi?id=510023https://exchange.xforce.ibmcloud.com/vulnerabilities/54700https://jira.jboss.org/jira/browse/JBAS-7105https://jira.jboss.org/jira/browse/JBPAPP-2274https://jira.jboss.org/jira/browse/JBPAPP-2284https://rhn.redhat.com/errata/RHSA-2009-1636.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1637.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1649.htmlhttps://rhn.redhat.com/errata/RHSA-2009-1650.html
2009-12-15
Published