CVE-2013-2102
published 2013-10-28CVE-2013-2102: The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is…
PriorityP413low3.3CVSS 2.0
AVAACLAuNCPINAN
EPSS
0.98%
58.4th percentile
The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_portal_platform | <= 6.0.0 | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
| redhat | jboss_enterprise_portal_platform | — | — |
CVSS provenance
nvdv2.03.3LOWAV:A/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wv8v-33h6-fw96: The default configuration of Red Hat JBoss Portal before 6
ghsa_unreviewed·2022-05-17
CVE-2013-2102 [LOW] CWE-287 GHSA-wv8v-33h6-fw96: The default configuration of Red Hat JBoss Portal before 6
The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.
Red Hat
Gatein: JGroups configurations enable diagnostics without authentication
vendor_redhat·2013-10-16·CVSS 3.3
CVE-2013-2102 [LOW] Gatein: JGroups configurations enable diagnostics without authentication
Gatein: JGroups configurations enable diagnostics without authentication
The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.
Package: Requirements (Red Hat JBoss Portal 5) - Will not fix
Package: Requirements (Red Hat JBoss Portal 6) - Affected
No detection rules found.
No public exploits indexed.
2013-10-28
Published