CVE-2011-4573: Low severity redhat JBoss Operations Network vulnerability
JON did not verify that a user had the proper modify resource permissions when they attempted to delete a plug-in configuration update from the group connection properties history.
Other sources
Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote authenticated users when deleting a plug-in configuration update from the group connection properties history, which prevents such activities from being recorded in the audit trail.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4573?
CVE-2011-4573 has been classified as a moderate security vulnerability.
How do I fix CVE-2011-4573?
To fix CVE-2011-4573, upgrade Red Hat JBoss Operations Network to version 2.4.2 or later.
What does CVE-2011-4573 affect?
CVE-2011-4573 affects all versions of Red Hat JBoss Operations Network prior to 2.4.2 and certain earlier versions.
What is the main issue with CVE-2011-4573?
The main issue with CVE-2011-4573 is the lack of proper permission enforcement for deleting plug-in configuration updates.
Can CVE-2011-4573 be exploited remotely?
Yes, CVE-2011-4573 can be exploited remotely if an unauthorized user attempts to delete configurations.