Início
Início
Tendências
Tendências
Vulnerabilidades
Vulnerabilidades
Notícias
Notícias
Pesquisadores
Pesquisadores
Por que dbugs?
Por que dbugs?
Configurações

Christian Schlüter

Pesquisador deVIADA
#40083de 56,334
7.5CVSS total
Vulnerabilidades · 1
PT-2012-1926
7.5
2012-11-23
Red Hat · Jboss Soa Platform · CVE-2011-4605
**Name of the Vulnerable Software and Affected Versions** JBoss Enterprise Application Platform versions 4.3.0 CP10 through 5.1.2 JBoss Web Platform version 5.1.2 JBoss SOA Platform versions 4.2.0.CP05 through 4.3.0.CP05 JBoss Portal Platform versions 4.3 CP07 through 5.2.x before 5.2.2 JBoss BRMS Platform version before 5.3.0 **Description** The issue affects the JNDI service, HA-JNDI service, and HAJNDIFactory invoker servlet, allowing remote attackers to modify items in a JNDI tree due to improper restriction of write access. **Recommendations** For JBoss Enterprise Application Platform versions 4.3.0 CP10 through 5.1.2, update to a version that properly restricts write access. For JBoss Web Platform version 5.1.2, update to a version that properly restricts write access. For JBoss SOA Platform versions 4.2.0.CP05 through 4.3.0.CP05, update to a version that properly restricts write access. For JBoss Portal Platform versions 4.3 CP07 through 5.2.x before 5.2.2, update to version 5.2.2 or later. For JBoss BRMS Platform version before 5.3.0, update to version 5.3.0 or later.