7.5
CVSSv2

CVE-2011-4608

Published: 27/01/2012 Updated: 13/02/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote malicious users to bypass intended access restrictions and provide malicious content, hijack sessions, and steal credentials by registering from an external vhost that does not enforce security constraints.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform 5.1.2

Vendor Advisories

Synopsis Important: mod_cluster-native security update Type/Severity Security Advisory: Important Topic An updated mod_cluster-native package that fixes one security issue is nowavailable for JBoss Enterprise Application Platform 512 for Red HatEnterprise Linux 4, 5, and 6The Red Hat Security Response Te ...
Synopsis Important: mod_cluster-native security update Type/Severity Security Advisory: Important Topic Updated mod_cluster packages that fix one security issue are now availablefor JBoss Enterprise Web Server 102 for Red Hat Enterprise Linux 4, 5,and 6The Red Hat Security Response Team has rated this up ...
Synopsis Important: mod_cluster-native security update Type/Severity Security Advisory: Important Topic An updated mod_cluster-native package that fixes one security issue is nowavailable for JBoss Enterprise Web Platform 512 for Red Hat EnterpriseLinux 4, 5, and 6The Red Hat Security Response Team has r ...