First published: Fri Aug 12 2011(Updated: )
Cross-site request forgery (CSRF) vulnerability in the JMX Console (jmx-console) in JBoss Enterprise Portal Platform before 5.2.2, BRMS Platform 5.3.0 before roll up patch1, and SOA Platform 5.3.0 allows remote authenticated users to hijack the authentication of arbitrary users for requests that perform operations on MBeans and possibly execute arbitrary code via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Enterprise Portal Platform | =5.0.0 | |
Redhat Jboss Enterprise Portal Platform | =5.1.1 | |
Redhat Jboss Enterprise Portal Platform | =5.1.0 | |
Redhat Jboss Enterprise Portal Platform | <=5.2.1 | |
Redhat Jboss Enterprise Brms Platform | =5.3.0 | |
Redhat Jboss Enterprise Portal Platform | =5.2.0 | |
Redhat Jboss Enterprise Soa Platform | =5.3.0 | |
Redhat Jboss Enterprise Portal Platform | =5.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.