CVE-2011-2908
published 2012-11-23CVE-2011-2908: Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before…
PriorityP181medium6CVSS 2.0
AVNACMAuSCPIPAP
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
1.57%
72.6th percentile
Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0 allows remote authenticated users to hijack the authentication of arbitrary users for requests that perform operations on MBeans and possibly execute arbitrary code via unspecified vectors.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_brms_platform | — | — |
| redhat | jboss_enterprise_portal_platform | <= 5.2.1 | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The JMX Console (/jmx-console) endpoint in JBoss EAP is the attack surface; monitor for unexpected or unauthenticated POST requests to this path, especially those invoking MBean operations such as WAR file deployment. ↗
- →Watch for CSRF-driven WAR file deployment via the JMX Console; an attacker tricks an admin-authenticated user into visiting a crafted page that submits a request to deploy an arbitrary WAR to the target JBoss server. ↗
- ·The CSRF vulnerability affects the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0. Ensure CSRF protections are applied to the jmx-console web application. ↗
- ·The broader CSRF concern for the JMX Console (CVE-2011-2908) is a superset of the earlier FileDeployment CSRF issue (CVE-2010-3878); environments patched only for CVE-2010-3878 remain exposed to the wider MBean invocation attack surface. ↗
CVSS provenance
nvdv2.06.0MEDIUMAV:N/AC:M/Au:S/C:P/I:P/A:P
vulncheck6.0MEDIUM
vendor_redhat6.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
CSRF on jmx-console allows invocation of operations on mbeans
vendor_redhat·2007-02-22·CVSS 6.0
CVE-2011-2908 [MEDIUM] CWE-352 CSRF on jmx-console allows invocation of operations on mbeans
CSRF on jmx-console allows invocation of operations on mbeans
Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0 allows remote authenticated users to hijack the authentication of arbitrary users for requests that perform operations on MBeans and possibly execute arbitrary code via unspecified vectors.
Package: Security (Red Hat JBoss BRMS 5) - Affected
Package: Security (Red Hat JBoss Portal 5) - Affected
Package: Security (Red Hat JBoss SOA Platform 5) - Affected
GHSA
GHSA-x3w9-v829-qphw: Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5
ghsa_unreviewed·2022-05-17
CVE-2011-2908 [MEDIUM] CWE-352 GHSA-x3w9-v829-qphw: Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5
Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0 allows remote authenticated users to hijack the authentication of arbitrary users for requests that perform operations on MBeans and possibly execute arbitrary code via unspecified vectors.
VulnCheck
Red Hat jboss_enterprise_brms_platform Cross-Site Request Forgery (CSRF)
vulncheck·2011·CVSS 6.0
CVE-2011-2908 [MEDIUM] Red Hat jboss_enterprise_brms_platform Cross-Site Request Forgery (CSRF)
Red Hat jboss_enterprise_brms_platform Cross-Site Request Forgery (CSRF)
Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0 allows remote authenticated users to hijack the authentication of arbitrary users for requests that perform operations on MBeans and possibly execute arbitrary code via unspecified vectors.
Affected: Red Hat jboss_enterprise_brms_platform
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://nsarchive.gwu.edu/sites/default/files/documents/5986978/Nati
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2908 CSRF on jmx-console allows invocation of operations on mbeans
bugzilla·2011-08-12·CVSS 6.0
CVE-2011-2908 [MEDIUM] CVE-2011-2908 CSRF on jmx-console allows invocation of operations on mbeans
CVE-2011-2908 CSRF on jmx-console allows invocation of operations on mbeans
The JMX console as shipped with JBoss EAP 5.1.1 is vulnerable to cross-site request forgery (CSRF) attacks. This vulnerability allows an attacker to invoke operations on mbeans via the JMX console.
Discussion:
This issue has been addressed in following products:
JBoss Enterprise SOA Platform 5.3.0
Via RHSA-2012:1152 https://rhn.redhat.com/errata/RHSA-2012-1152.html
---
This issue has been addressed in following products:
JBoss Enterprise BRMS Platform 5.3.0
Via RHSA-2012:1165 https://rhn.redhat.com/errata/RHSA-2012-1165.html
---
This issue has been addressed in following products:
JBoss Enterprise Portal Platform 5.2.2
Via RHSA-2012:1232 https://rhn.redhat.com/errata/RHSA-2012-1232.html
---
This issu
Bugzilla
CVE-2010-3878 JBoss EAP jmx console FileDeployment CSRF
bugzilla·2010-06-16·CVSS 4.3
CVE-2010-3878 [MEDIUM] CVE-2010-3878 JBoss EAP jmx console FileDeployment CSRF
CVE-2010-3878 JBoss EAP jmx console FileDeployment CSRF
A Cross-Site Request Forgery (CSRF) flaw was found in the JMX Console. A remote attacker could use this flaw to deploy a WAR file of their choosing on the target server, if they are able to trick a user, who is logged into the JMX Console as the admin user, into visiting a specially-crafted web page.
Discussion:
This issue has been addressed in following products:
JBEAP 4.3.0 for RHEL 4
Via RHSA-2010:0937 https://rhn.redhat.com/errata/RHSA-2010-0937.html
---
This issue has been addressed in following products:
JBEAP 4.3.0 for RHEL 5
Via RHSA-2010:0938 https://rhn.redhat.com/errata/RHSA-2010-0938.html
---
This issue has been addressed in following products:
JBoss Enterprise Application Platform 4.3.0
Via RHSA-2010:0939 htt
http://rhn.redhat.com/errata/RHSA-2012-1152.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1165.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1232.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://secunia.com/advisories/50230http://secunia.com/advisories/50549http://secunia.com/advisories/51984http://www.osvdb.org/84530http://www.securityfocus.com/bid/54915https://bugzilla.redhat.com/show_bug.cgi?id=730176https://exchange.xforce.ibmcloud.com/vulnerabilities/77549http://rhn.redhat.com/errata/RHSA-2012-1152.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1165.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1232.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://secunia.com/advisories/50230http://secunia.com/advisories/50549http://secunia.com/advisories/51984http://www.osvdb.org/84530http://www.securityfocus.com/bid/54915https://bugzilla.redhat.com/show_bug.cgi?id=730176https://exchange.xforce.ibmcloud.com/vulnerabilities/77549
2012-11-23
Published
Exploited in the wild