6.4 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:P/A:N
0.007 Low
EPSS
Percentile
80.6%
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly
cache EJB invocations by the EJB client API, which allows remote attackers
to hijack sessions by using an EJB client.
Author | Note |
---|---|
jdstrand | per Debian, only builds a few libraries, not the full application server |