First published: Wed Aug 22 2012(Updated: )
McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to execute arbitrary code via a crafted .war file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee SmartFilter | <=4.2.1 | |
McAfee SmartFilter | <=4.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4599 is rated as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2012-4599, update McAfee SmartFilter Administration to version 4.2.1.01 or later.
CVE-2012-4599 affects McAfee SmartFilter Administration and SmartFilter Administration Bess Edition versions up to 4.2.1.
Yes, CVE-2012-4599 can be exploited remotely by attackers who can access the unsecured JBoss RMI interface.
CVE-2012-4599 allows attackers to execute arbitrary code on the server by deploying a crafted .war file.