CVE-2012-2377: Low severity red hat jboss portal vulnerability
JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.
Other sources
When a JGroups channel is started, the JGroups diagnostics service will be enabled by default with no authentication. This service is exposed via IP multicast. On JBoss Enterprise Application Platform 6, an attacker on an adjacent network can exploit this flaw to read diagnostics information and invoke JMX operations on the server (limited remote code execution). On other affected JBoss products, an attacker on an adjacent network can exploit this flaw only to read diagnostics information (information disclosure).
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2377?
CVE-2012-2377 is categorized as a high severity vulnerability that could allow unauthorized access to sensitive diagnostics information.
How do I fix CVE-2012-2377?
To fix CVE-2012-2377, update your affected JBoss software to the latest version that includes security patches.
What versions are affected by CVE-2012-2377?
CVE-2012-2377 affects several versions of JBoss Enterprise Portal Platform, SOA Platform, and BRMS Platform prior to specified version limits.
What kind of information can be accessed due to CVE-2012-2377?
CVE-2012-2377 allows remote attackers to read sensitive diagnostics information which may aid in further attacks.
Is authentication required for exploiting CVE-2012-2377?
No, CVE-2012-2377 can be exploited without authentication, posing a significant risk to vulnerable systems.