Lucene search

K
cve[email protected]CVE-2012-0062
HistoryFeb 14, 2014 - 3:55 p.m.

CVE-2012-0062

2014-02-1415:55:04
CWE-287
web.nvd.nist.gov
25
cve-2012-0062
red hat jboss
operations network
jon
remote attackers
hijack
agent sessions
security token

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.9 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.6%

Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.

Affected configurations

NVD
Node
redhatjboss_operations_networkRangeโ‰ค2.4.1
OR
redhatjboss_operations_networkMatch2.0.0
OR
redhatjboss_operations_networkMatch2.0.1
OR
redhatjboss_operations_networkMatch2.1.0
OR
redhatjboss_operations_networkMatch2.2
OR
redhatjboss_operations_networkMatch2.3
OR
redhatjboss_operations_networkMatch2.3.1
OR
redhatjboss_operations_networkMatch2.4
OR
redhatjboss_operations_networkMatch3.0

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.9 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

71.6%

Related for CVE-2012-0062