CVE-2011-4573

CWE-2645 documents5 sources
Severity
3.5LOW
EPSS
0.1%
top 67.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1
Latest updateMay 17

Description

Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote authenticated users when deleting a plug-in configuration update from the group connection properties history, which prevents such activities from being recorded in the audit trail.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 6.8 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-5298-jrhg-c6hc: Red Hat JBoss Operations Network (JON) before 22022-05-17
CVEList
CVE-2011-4573: Red Hat JBoss Operations Network (JON) before 22014-04-01

📋Vendor Advisories

1
Red Hat
JON: Incorrect delete permissions check2011-12-08

💬Community

1
Bugzilla
CVE-2011-4573 JON: Incorrect delete permissions check2011-12-05