Description
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agents via the registered agent name.
CVSS vector
AV:N/AC:M/C:P/I:P/A:NExploitability: 8.6 | Impact: 4.9 Affected Packages1 packages
๐ดVulnerability Details
2GHSAGHSA-fhpq-g3rr-xhmq: Red Hat JBoss Operations Network (JON) before 2โ2022-05-04 โถ CVEListCVE-2012-0052: Red Hat JBoss Operations Network (JON) before 2โ2014-02-14 โถ ๐Vendor Advisories
2Red HatJON: Unapproved agents can connect using the name of an existing approved agentโ2012-02-01 โถ Red Hatkernel: proc: /proc/<pid>/mem mem_write insufficient permission checkingโ2012-01-18 โถ ๐ฌCommunity
3BugzillaCVE-2012-4401 moodle: Course topics permission issue (MSA-12-0052)โ2012-09-17 โถ BugzillaCVE-2012-2922 drupal7: full path disclosure vulnerabilityโ2012-05-23 โถ BugzillaCVE-2012-0052 JON: Unapproved agents can connect using the name of an existing approved agentโ2012-01-16 โถ