cbcvebase.
CVE-2011-2908
published 2012-11-23

CVE-2011-2908: Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before…

PriorityP181medium6CVSS 2.0
AVNACMAuSCPIPAP
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
1.57%
72.6th percentile
Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0 allows remote authenticated users to hijack the authentication of arbitrary users for requests that perform operations on MBeans and possibly execute arbitrary code via unspecified vectors.

Affected

8 ranges
VendorProductVersion rangeFixed in
redhatjboss_enterprise_brms_platform
redhatjboss_enterprise_portal_platform<= 5.2.1
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_soa_platform

Detection & IOCsextracted from sources · hover to see the quote

  • The JMX Console (/jmx-console) endpoint in JBoss EAP is the attack surface; monitor for unexpected or unauthenticated POST requests to this path, especially those invoking MBean operations such as WAR file deployment.
  • Watch for CSRF-driven WAR file deployment via the JMX Console; an attacker tricks an admin-authenticated user into visiting a crafted page that submits a request to deploy an arbitrary WAR to the target JBoss server.
  • ·The CSRF vulnerability affects the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0. Ensure CSRF protections are applied to the jmx-console web application.
  • ·The broader CSRF concern for the JMX Console (CVE-2011-2908) is a superset of the earlier FileDeployment CSRF issue (CVE-2010-3878); environments patched only for CVE-2010-3878 remain exposed to the wider MBean invocation attack surface.

CVSS provenance

nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vulncheck6.0MEDIUM
vendor_redhat6.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.