CVE-2012-0089
published 2012-01-18CVE-2012-0089: Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect…
PriorityP414medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
0.98%
58.2th percentile
Unspecified vulnerability in the PeopleSoft Enterprise HCM component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to ePerformance.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | peoplesoft_products | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-0062 JON: Unapproved agents can hijack an approved agent's endpoint by using a null security token
bugzilla·2012-01-19·CVSS 5.8
CVE-2012-0062 [MEDIUM] CVE-2012-0062 JON: Unapproved agents can hijack an approved agent's endpoint by using a null security token
CVE-2012-0062 JON: Unapproved agents can hijack an approved agent's endpoint by using a null security token
The JON server allows agent registration to succeed under certain conditions if the registration request does not include a security token. This is a feature designed to add convenience. A remote attacker could exploit this by spoofing the identify of an approved agent and passing a null security token, allowing them to hijack the approved agent's session and steal its security token.
Discussion:
This issue has been addressed in following products:
JBoss Operations Network 2.4.2
Via RHSA-2012:0089 https://rhn.redhat.com/errata/RHSA-2012-0089.html
---
This issue has been addressed in following products:
JBoss Operations Network 3.0.1
Via RHSA-2012:0406 https://rhn.redhat.com/
Bugzilla
CVE-2012-0052 JON: Unapproved agents can connect using the name of an existing approved agent
bugzilla·2012-01-16·CVSS 5.8
CVE-2012-0052 [MEDIUM] CVE-2012-0052 JON: Unapproved agents can connect using the name of an existing approved agent
CVE-2012-0052 JON: Unapproved agents can connect using the name of an existing approved agent
If a JON agent is registered in a JON server's inventory with a given name, then any other agent can connect to the JON server and assume the identity of this registered agent simply by assuming its agent name. The JON agent key is not verified, allowing malicious JON agents to connect to the server.
Discussion:
This issue has been addressed in following products:
JBoss Operations Network 2.4.2
Via RHSA-2012:0089 https://rhn.redhat.com/errata/RHSA-2012-0089.html
---
This issue has been addressed in following products:
JBoss Operations Network 3.0.1
Via RHSA-2012:0406 https://rhn.redhat.com/errata/RHSA-2012-0406.html
Bugzilla
CVE-2011-4573 JON: Incorrect delete permissions check
bugzilla·2011-12-05·CVSS 3.5
CVE-2011-4573 [LOW] CVE-2011-4573 JON: Incorrect delete permissions check
CVE-2011-4573 JON: Incorrect delete permissions check
JON did not verify that a user had the proper modify resource permissions when they attempted to delete a plug-in configuration update from the group connection properties history.
Discussion:
Patch commit:
http://git.fedorahosted.org/git/?p=rhq/rhq.git;a=commitdiff;h=24ba99780531d2f187528d7b555d79fab807467b
---
JON (RHQ) BZs:
https://bugzilla.redhat.com/show_bug.cgi?id=617649
https://bugzilla.redhat.com/show_bug.cgi?id=617653
---
This issue has been resolved in JON 3.0. A fix for this issue may be included in a future update for JON 2.4.1.
---
This issue has been addressed in following products:
JBoss Operations Network 2.4.2
Via RHSA-2012:0089 https://rhn.redhat.com/errata/RHSA-2012-0089.html
Bugzilla
CVE-2011-3206 JON: Multiple XSS flaws
bugzilla·2011-08-31·CVSS 4.3
CVE-2011-3206 [MEDIUM] CVE-2011-3206 JON: Multiple XSS flaws
CVE-2011-3206 JON: Multiple XSS flaws
Multiple cross-site scripting (XSS) flaws were found in the JON administration interface. If a remote attacker could trick a user, who was logged into the JON administration interface, into visiting a specially-crafted URL, it would lead to arbitrary web script execution in the context of the user's JON session.
Discussion:
This issue has been resolved in JON 3.0.
---
This issue has been addressed in following products:
JBoss Operations Network 2.4.2
Via RHSA-2012:0089 https://rhn.redhat.com/errata/RHSA-2012-0089.html
2012-01-18
Published