cbcvebase.
CVE-2012-2377
published 2012-11-23

CVE-2012-2377: JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without…

PriorityP417low3.3CVSS 2.0
AVAACLAuNCPINAN
EPSS
1.45%
70.4th percentile
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.

Affected

16 ranges
VendorProductVersion rangeFixed in
redhatjboss_enterprise_brms_platform<= 5.2.0
redhatjboss_enterprise_portal_platform<= 5.2.1
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_soa_platform<= 5.2.0
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform

CVSS provenance

nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.