CVE-2013-2102

Severity
3.3LOW
EPSS
0.1%
top 66.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 28
Latest updateMay 17

Description

The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.

CVSS vector

AV:A/AC:L/C:P/I:N/A:NExploitability: 6.5 | Impact: 2.9

Affected Packages1 packages

๐Ÿ”ดVulnerability Details

2
GHSA
GHSA-wv8v-33h6-fw96: The default configuration of Red Hat JBoss Portal before 6โ†—2022-05-17
โ–ถ
CVEList
CVE-2013-2102: The default configuration of Red Hat JBoss Portal before 6โ†—2013-10-28
โ–ถ

๐Ÿ“‹Vendor Advisories

1
Red Hat
Gatein: JGroups configurations enable diagnostics without authenticationโ†—2013-10-16
โ–ถ

๐Ÿ’ฌCommunity

1
Bugzilla
CVE-2013-2102 Gatein: JGroups configurations enable diagnostics without authenticationโ†—2013-05-16
โ–ถ