CVE-2012-2377
published 2012-11-23CVE-2012-2377: JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without…
PriorityP417low3.3CVSS 2.0
AVAACLAuNCPINAN
EPSS
1.45%
70.4th percentile
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_brms_platform | <= 5.2.0 | — |
| redhat | jboss_enterprise_portal_platform | <= 5.2.1 | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_soa_platform | <= 5.2.0 | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
CVSS provenance
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JGroups diagnostics service enabled by default with no authentication when a JGroups channel is started
vendor_redhat·2012-06-12·CVSS 3.3
CVE-2012-2377 [LOW] JGroups diagnostics service enabled by default with no authentication when a JGroups channel is started
JGroups diagnostics service enabled by default with no authentication when a JGroups channel is started
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.
Package: Security (Red Hat JBoss BRMS 5) - Affected
Package: Requirements (Red Hat JBoss Portal 5) - Affected
Package: Security (Red Hat JBoss SOA Platform 5) - Affected
GHSA
GHSA-jm5c-rgfp-cjhx: JGroups diagnostics service in JBoss Enterprise Portal Platform before 5
ghsa_unreviewed·2022-05-17
CVE-2012-2377 [LOW] CWE-287 GHSA-jm5c-rgfp-cjhx: JGroups diagnostics service in JBoss Enterprise Portal Platform before 5
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2012-1028.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1125.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1232.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://secunia.com/advisories/49669http://secunia.com/advisories/50084http://secunia.com/advisories/50549http://secunia.com/advisories/51984http://www.osvdb.org/83085http://www.securityfocus.com/bid/54183https://bugzilla.redhat.com/show_bug.cgi?id=823392https://exchange.xforce.ibmcloud.com/vulnerabilities/76540http://rhn.redhat.com/errata/RHSA-2012-1028.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1125.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1232.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0191.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0192.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0193.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0194.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0195.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0196.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0197.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0198.htmlhttp://secunia.com/advisories/49669http://secunia.com/advisories/50084http://secunia.com/advisories/50549http://secunia.com/advisories/51984http://www.osvdb.org/83085http://www.securityfocus.com/bid/54183https://bugzilla.redhat.com/show_bug.cgi?id=823392https://exchange.xforce.ibmcloud.com/vulnerabilities/76540
2012-11-23
Published