CVE-2012-2377

Severity
3.3LOW
EPSS
1.0%
top 23.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 23
Latest updateMay 17

Description

JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.

CVSS vector

AV:A/AC:L/C:P/I:N/A:NExploitability: 6.5 | Impact: 2.9

🔴Vulnerability Details

2
GHSA
GHSA-jm5c-rgfp-cjhx: JGroups diagnostics service in JBoss Enterprise Portal Platform before 52022-05-17
CVEList
CVE-2012-2377: JGroups diagnostics service in JBoss Enterprise Portal Platform before 52012-11-23

📋Vendor Advisories

1
Red Hat
JGroups diagnostics service enabled by default with no authentication when a JGroups channel is started2012-06-12

💬Community

1
Bugzilla
CVE-2012-2377 JGroups diagnostics service enabled by default with no authentication when a JGroups channel is started2012-05-21
CVE-2012-2377 (LOW CVSS 3.3) | JGroups diagnostics service in JBos | cvebase.io