CVE-2011-2908

Severity
6.0MEDIUM
EPSS
0.7%
top 27.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23
Latest updateMay 17

Description

Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0 allows remote authenticated users to hijack the authentication of arbitrary users for requests that perform operations on MBeans and possibly execute arbitrary code via unspecified vectors.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

🔴Vulnerability Details

3
GHSA
GHSA-x3w9-v829-qphw: Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 52022-05-17
CVEList
CVE-2011-2908: Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 52012-11-23
VulnCheck
Red Hat jboss_enterprise_brms_platform Cross-Site Request Forgery (CSRF)2011

📋Vendor Advisories

1
Red Hat
CSRF on jmx-console allows invocation of operations on mbeans2007-02-22

💬Community

1
Bugzilla
CVE-2011-2908 CSRF on jmx-console allows invocation of operations on mbeans2011-08-12
CVE-2011-2908 (MEDIUM CVSS 6) | Cross-site request forgery (CSRF) v | cvebase.io