CVE-2013-4128
published 2013-08-16CVE-2013-4128: Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack…
PriorityP335medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.44%
82.5th percentile
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
remote-naming: Session fixation due improper connection caching
vendor_redhat·2013-07-11·CVSS 6.4
CVE-2013-4128 [MEDIUM] CWE-384 remote-naming: Session fixation due improper connection caching
remote-naming: Session fixation due improper connection caching
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.
Package: remote-naming (Red Hat JBoss Data Grid 6) - Not affected
Package: remote-naming (Red Hat JBoss Portal 6) - Affected
GHSA
GHSA-mj2q-jjfm-w2rq: Red Hat JBoss Enterprise Application Platform (EAP) 6
ghsa_unreviewed·2022-05-17
CVE-2013-4128 [MEDIUM] GHSA-mj2q-jjfm-w2rq: Red Hat JBoss Enterprise Application Platform (EAP) 6
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.
No detection rules found.
No public exploits indexed.
http://osvdb.org/96217http://rhn.redhat.com/errata/RHSA-2013-1151.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1152.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://secunia.com/advisories/54508http://www.securitytracker.com/id/1028898https://bugzilla.redhat.com/show_bug.cgi?id=984795https://exchange.xforce.ibmcloud.com/vulnerabilities/86386http://osvdb.org/96217http://rhn.redhat.com/errata/RHSA-2013-1151.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1152.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://secunia.com/advisories/54508http://www.securitytracker.com/id/1028898https://bugzilla.redhat.com/show_bug.cgi?id=984795https://exchange.xforce.ibmcloud.com/vulnerabilities/86386
2013-08-16
Published