Lucene search

K
cve[email protected]CVE-2011-4605
HistoryNov 23, 2012 - 8:55 p.m.

CVE-2011-4605

2012-11-2320:55:01
CWE-264
web.nvd.nist.gov
35
cve-2011-4605
jboss
eap
web platform
soa platform
portal platform
brms platform
security vulnerability
remote attack

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.7%

The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2.2, and BRMS Platform before 5.3.0 do not properly restrict write access, which allows remote attackers to add, delete, or modify items in a JNDI tree via unspecified vectors.

Affected configurations

NVD
Node
redhatjboss_enterprise_application_platformMatch4.3.0cp10
OR
redhatjboss_enterprise_application_platformMatch5.1.2
OR
redhatjboss_enterprise_brms_platformRangeโ‰ค5.2.0
OR
redhatjboss_enterprise_portal_platformMatch4.3.0cp07
OR
redhatjboss_enterprise_portal_platformMatch5.2.0
OR
redhatjboss_enterprise_portal_platformMatch5.2.1
OR
redhatjboss_enterprise_soa_platformMatch4.2.0cp05
OR
redhatjboss_enterprise_soa_platformMatch4.3.0cp05
OR
redhatjboss_enterprise_web_platformMatch5.1.2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.7%