Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23989
HistoryApr 10, 2020 - 12:42 a.m.

Information Disclosure

2020-04-1000:42:53
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
29

EPSS

0.968

Percentile

99.7%

JMX-console is vulnerable to information disclosure. The JMX Console configuration only specified an authentication requirement for requests that used the GET and POST HTTP “verbs”. A remote attacker could create an HTTP request that does not specify GET or POST, causing it to be executed by the default GET handler without authentication. This release contains a JMX Console with an updated configuration that no longer specifies the HTTP verbs. This means that the authentication requirement is applied to all requests.

References