CVE-2013-4213
published 2013-08-16CVE-2013-4213: Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to…
PriorityP335medium6.4CVSS 2.0
AVNACLAuNCPIPAN
EPSS
2.47%
82.7th percentile
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-36g9-q537-hg7w: Red Hat JBoss Enterprise Application Platform (EAP) 6
ghsa_unreviewed·2022-05-17
CVE-2013-4213 [MEDIUM] CWE-284 GHSA-36g9-q537-hg7w: Red Hat JBoss Enterprise Application Platform (EAP) 6
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
Red Hat
ejb-client: Session fixation due improper connection caching
vendor_redhat·2013-06-27·CVSS 6.4
CVE-2013-4213 [MEDIUM] CWE-384 ejb-client: Session fixation due improper connection caching
ejb-client: Session fixation due improper connection caching
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
Package: remote-naming (Red Hat JBoss Data Grid 6) - Not affected
Package: remote-naming (Red Hat JBoss Portal 6) - Affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6348 Apache Struts2: XSS via malicious action parameter
bugzilla·2013-11-04·CVSS 4.3
CVE-2013-6348 [MEDIUM] CVE-2013-6348 Apache Struts2: XSS via malicious action parameter
CVE-2013-6348 Apache Struts2: XSS via malicious action parameter
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts2 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to actionNames.action and showConfig.action in config-browser/.
Affects: Versions >=2.0.0 and <=2.3.15.3
Fixed In: 2.3.16
Upstream Bug: https://issues.apache.org/jira/browse/WW-4213
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6348
http://seclists.org/fulldisclosure/2013/Oct/244
http://en.wooyun.org/bugs/wooyun-2013-034?2592
http://packetstormsecurity.com/files/123805/Struts-2.3.15.3-Cross-Site-Scripting.html
http://osvdb.org/99047
http://osvdb.org/99048
Discussion:
Statement:
A previous statement by Red Hat related to this CVE, prior to A
Bugzilla
CVE-2013-4213 JBoss ejb-client: Session fixation due improper connection caching
bugzilla·2013-07-17·CVSS 6.4
CVE-2013-4213 [MEDIUM] CVE-2013-4213 JBoss ejb-client: Session fixation due improper connection caching
CVE-2013-4213 JBoss ejb-client: Session fixation due improper connection caching
A flaw was discovered in the way connections for remote EJB invocations via the EJB client API were cached on the server. A remote attacker could exploit this flaw by using an EJB client to get a previously authenticated connection.
Discussion:
Acknowledgements:
This issue was discovered by Wolf-Dieter Fink of the Red Hat GSS Team.
---
This issue has been addressed in following products:
Red Hat JBoss Enterprise Application Platform 6.1.0
Via RHSA-2013:1152 https://rhn.redhat.com/errata/RHSA-2013-1152.html
---
This issue has been addressed in following products:
JBEAP 6 for RHEL 5
JBEAP 6 for RHEL 6
Via RHSA-2013:1151 https://rhn.redhat.com/errata/RHSA-2013-1151.html
---
This issue has been addre
http://osvdb.org/96216http://rhn.redhat.com/errata/RHSA-2013-1151.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1152.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://secunia.com/advisories/54508http://www.securitytracker.com/id/1028898https://bugzilla.redhat.com/show_bug.cgi?id=985359https://exchange.xforce.ibmcloud.com/vulnerabilities/86387http://osvdb.org/96216http://rhn.redhat.com/errata/RHSA-2013-1151.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1152.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1437.htmlhttp://secunia.com/advisories/54508http://www.securitytracker.com/id/1028898https://bugzilla.redhat.com/show_bug.cgi?id=985359https://exchange.xforce.ibmcloud.com/vulnerabilities/86387
2013-08-16
Published