cbcvebase.
CVE-2012-2377
published 2012-11-23

CVE-2012-2377: JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without…

low3.3CVSS 3.1
AVAACLAuNCPINAN
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.

Affected

16 ranges
VendorProductVersion rangeFixed in
redhatjboss_enterprise_brms_platform<= 5.2.0
redhatjboss_enterprise_portal_platform<= 5.2.1
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_portal_platform
redhatjboss_enterprise_soa_platform<= 5.2.0
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform