First published: Mon Dec 05 2011(Updated: )
JON did not verify that a user had the proper modify resource permissions when they attempted to delete a plug-in configuration update from the group connection properties history.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Operations Network | <=2.4.1 | |
Red Hat JBoss Operations Network | =1.0.0 | |
Red Hat JBoss Operations Network | =2.0.0 | |
Red Hat JBoss Operations Network | =2.0.1 | |
Red Hat JBoss Operations Network | =2.1.0 | |
Red Hat JBoss Operations Network | =2.2 | |
Red Hat JBoss Operations Network | =2.3 | |
Red Hat JBoss Operations Network | =2.3.1 | |
Red Hat JBoss Operations Network | =2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4573 has been classified as a moderate security vulnerability.
To fix CVE-2011-4573, upgrade Red Hat JBoss Operations Network to version 2.4.2 or later.
CVE-2011-4573 affects all versions of Red Hat JBoss Operations Network prior to 2.4.2 and certain earlier versions.
The main issue with CVE-2011-4573 is the lack of proper permission enforcement for deleting plug-in configuration updates.
Yes, CVE-2011-4573 can be exploited remotely if an unauthorized user attempts to delete configurations.