4.3
CVSSv2

CVE-2012-1154

Published: 22/10/2012 Updated: 08/11/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

mod_cluster 1.0.10 prior to 1.0.10 CP03 and 1.1.x prior to 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote malicious users to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform 5.1.2

redhat mod cluster 1.1.0

redhat mod cluster 1.1.1

redhat mod cluster 1.1.2

redhat mod cluster 1.1.3

redhat mod cluster 1.1.4

redhat mod cluster 1.0.10

Vendor Advisories

Synopsis Moderate: mod_cluster security update Type/Severity Security Advisory: Moderate Topic Updated mod_cluster packages that fix one security issue are now availablefor JBoss Enterprise Web Platform 512 for Red Hat Enterprise Linux 4, 5,and 6The Red Hat Security Response Team has rated this update as ...
Synopsis Moderate: mod_cluster security update Type/Severity Security Advisory: Moderate Topic Updated mod_cluster packages that fix one security issue are now availablefor JBoss Enterprise Application Platform 512 for Red HatEnterprise Linux 4, 5, and 6The Red Hat Security Response Team has rated this u ...
Synopsis Moderate: mod_cluster security update Type/Severity Security Advisory: Moderate Topic Updated mod_cluster packages that fix one security issue are now availablefor JBoss Enterprise Web Server 102 for Red Hat Enterprise Linux 5 and 6The Red Hat Security Response Team has rated this update as havi ...