5.4
CVSSv2

CVE-2013-4112

Published: 28/09/2013 Updated: 08/03/2014
CVSS v2 Base Score: 5.4 | Impact Score: 6.4 | Exploitability Score: 5.5
VMScore: 481
Vector: AV:A/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The DiagnosticsHandler in JGroup 3.0.x, 3.1.x, 3.2.x prior to 3.2.9, and 3.3.x prior to 3.3.3 allows remote malicious users to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jgroups jgroup 3.0.6

jgroups jgroup 3.0.7

jgroups jgroup 3.0.14

jgroups jgroup 3.1.0

jgroups jgroup 3.2.7

jgroups jgroup 3.2.8

jgroups jgroup 3.0.4

jgroups jgroup 3.0.5

jgroups jgroup 3.0.12

jgroups jgroup 3.0.13

jgroups jgroup 3.2.5

jgroups jgroup 3.2.6

jgroups jgroup 3.0.2

jgroups jgroup 3.0.3

jgroups jgroup 3.0.10

jgroups jgroup 3.0.11

jgroups jgroup 3.2.3

jgroups jgroup 3.2.4

jgroups jgroup 3.3.2

jgroups jgroup 3.0.0

jgroups jgroup 3.0.1

jgroups jgroup 3.0.8

jgroups jgroup 3.0.9

jgroups jgroup 3.2.0

jgroups jgroup 3.2.1

jgroups jgroup 3.2.2

jgroups jgroup 3.3.0

jgroups jgroup 3.3.1

redhat jboss enterprise application platform 6.1.0

Vendor Advisories

Debian Bug report logs - #717031 libjgroups-java: CVE-2013-4112 Package: libjgroups-java; Maintainer for libjgroups-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Source for libjgroups-java is src:libjgroups-java (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> D ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 611 update Type/Severity Security Advisory: Moderate Topic Red Hat JBoss Enterprise Application Platform 611, which fixes multiplesecurity issues, various bugs, and adds enhancements, is now available forRed Hat Enterprise Linux 6The Red ...
Synopsis Moderate: Red Hat JBoss Enterprise Application Platform 611 update Type/Severity Security Advisory: Moderate Topic Red Hat JBoss Enterprise Application Platform 611, which fixes multiplesecurity issues, various bugs, and adds enhancements, is now available forRed Hat Enterprise Linux 5The Red ...
The DiagnosticsHandler in JGroup 30x, 31x, 32x before 329, and 33x before 333 allows remote attackers to obtain sensitive information (diagnostic information) and execute arbitrary code by reusing valid credentials ...