cbcvebase.
CVE-2012-1154
published 2012-10-22

CVE-2012-1154: mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts…

PriorityP430medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
2.59%
83.6th percentile
mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.

Affected

7 ranges
VendorProductVersion rangeFixed in
redhatjboss_enterprise_application_platform
redhatmod_cluster
redhatmod_cluster
redhatmod_cluster
redhatmod_cluster
redhatmod_cluster
redhatmod_cluster

CVSS provenance

nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.