CVE-2012-0062
published 2014-02-14CVE-2012-0062: Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request…
PriorityP429medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.12%
62.5th percentile
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_operations_network | <= 2.4.1 | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
| redhat | jboss_operations_network | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2c3w-hjxh-5rqg: Red Hat JBoss Operations Network (JON) before 2
ghsa_unreviewed·2022-05-04
CVE-2012-0062 [MEDIUM] CWE-287 GHSA-2c3w-hjxh-5rqg: Red Hat JBoss Operations Network (JON) before 2
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.
Red Hat
JON: Unapproved agents can hijack an approved agent's endpoint by using a null security token
vendor_redhat·2012-02-01·CVSS 5.8
CVE-2012-0062 [MEDIUM] JON: Unapproved agents can hijack an approved agent's endpoint by using a null security token
JON: Unapproved agents can hijack an approved agent's endpoint by using a null security token
Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.
Package: Security (Red Hat JBoss BRMS 5) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5471 moodle: Various security issues fixed in upstream 2.3.3, 2.2.6 and 2.1.9 versions (MSA-12-0057, MSA-12-0058, MSA-12-0059, MSA-12-0060, MSA-12-0061, MSA-12-0062, MSA-12-0063) [fedora-all]
bugzilla·2012-11-19·CVSS 6.5
CVE-2012-5471 [MEDIUM] CVE-2012-5471 moodle: Various security issues fixed in upstream 2.3.3, 2.2.6 and 2.1.9 versions (MSA-12-0057, MSA-12-0058, MSA-12-0059, MSA-12-0060, MSA-12-0061, MSA-12-0062, MSA-12-0063) [fedora-all]
CVE-2012-5471 moodle: Various security issues fixed in upstream 2.3.3, 2.2.6 and 2.1.9 versions (MSA-12-0057, MSA-12-0058, MSA-12-0059, MSA-12-0060, MSA-12-0061, MSA-12-0062, MSA-12-0063) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also
Bugzilla
CVE-2012-0062 JON: Unapproved agents can hijack an approved agent's endpoint by using a null security token
bugzilla·2012-01-19·CVSS 5.8
CVE-2012-0062 [MEDIUM] CVE-2012-0062 JON: Unapproved agents can hijack an approved agent's endpoint by using a null security token
CVE-2012-0062 JON: Unapproved agents can hijack an approved agent's endpoint by using a null security token
The JON server allows agent registration to succeed under certain conditions if the registration request does not include a security token. This is a feature designed to add convenience. A remote attacker could exploit this by spoofing the identify of an approved agent and passing a null security token, allowing them to hijack the approved agent's session and steal its security token.
Discussion:
This issue has been addressed in following products:
JBoss Operations Network 2.4.2
Via RHSA-2012:0089 https://rhn.redhat.com/errata/RHSA-2012-0089.html
---
This issue has been addressed in following products:
JBoss Operations Network 3.0.1
Via RHSA-2012:0406 https://rhn.redhat.com/
2014-02-14
Published