Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.801987
Category:Web Servers
Title:Red Hat JBoss Products Multiple Vulnerabilities (status page) - Active Check
Summary:Red Hat JBoss products are prone to multiple vulnerabilities.
Description:Summary:
Red Hat JBoss products are prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws are due to the following:

- A publicly accessible status page. This leads to leakage of logs of last connections and (in
second case) leakage of all services (with their paths) on the server.

- There is no protection against Brute Force attacks at these resources and other private
resources with BF vulnerability. The list of all resources of concrete server can be found at
page status?full=true.

Note: CVE-2010-1429 exists because of a CVE-2008-3273 regression.

Vulnerability Impact:
Successful exploitation will allow an attacker to access
sensitive information like e.g. services with their paths on the server.

Affected Software/OS:
Red Hat JBoss Application Server (AS) as used by e.g. Red Hat
JBoss Enterprise Application Platform (EAP).

Solution:
Updates are available. Please see the references for details.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2008-3273
1020628
http://www.securitytracker.com/id?1020628
30540
http://www.securityfocus.com/bid/30540
HPSBMU02736
http://marc.info/?l=bugtraq&m=132698550418872&w=2
RHSA-2008:0825
http://rhn.redhat.com/errata/RHSA-2008-0825.html
RHSA-2008:0826
http://rhn.redhat.com/errata/RHSA-2008-0826.html
RHSA-2008:0827
http://rhn.redhat.com/errata/RHSA-2008-0827.html
RHSA-2008:0828
http://rhn.redhat.com/errata/RHSA-2008-0828.html
SSRT100699
http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.2.0.cp03/html-single/readme/index.html
http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.3.0.cp01/html-single/readme/
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=457757
https://jira.jboss.org/jira/browse/JBPAPP-544
jbosseap-statusservlet-info-disclosure(44235)
https://exchange.xforce.ibmcloud.com/vulnerabilities/44235
Common Vulnerability Exposure (CVE) ID: CVE-2010-1429
1023918
http://securitytracker.com/id?1023918
39563
http://secunia.com/advisories/39563
39710
http://www.securityfocus.com/bid/39710
44009
https://www.exploit-db.com/exploits/44009/
ADV-2010-0992
http://www.vupen.com/english/advisories/2010/0992
RHSA-2010:0376
https://rhn.redhat.com/errata/RHSA-2010-0376.html
RHSA-2010:0377
https://rhn.redhat.com/errata/RHSA-2010-0377.html
RHSA-2010:0378
https://rhn.redhat.com/errata/RHSA-2010-0378.html
RHSA-2010:0379
https://rhn.redhat.com/errata/RHSA-2010-0379.html
https://bugzilla.redhat.com/show_bug.cgi?id=585900
jboss-status-servlet-information-disclosure(58149)
https://exchange.xforce.ibmcloud.com/vulnerabilities/58149
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.