First published: Tue Oct 01 2013(Updated: )
The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other products allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
JBoss Enterprise Application Platform | =5.0.0 | |
Red Hat JBoss Enterprise BRMS Platform | =5.2.0 | |
Red Hat JBoss Enterprise BRMS Platform | =5.3.0 | |
Red Hat JBoss Enterprise SOA Platform | =5.3.0 | |
Red Hat JBoss Enterprise SOA Platform | =5.3.1 | |
Red Hat JBoss Enterprise Web Platform | =5.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4210 is classified as a moderate severity vulnerability.
To fix CVE-2013-4210, update to the latest patched version of the affected JBoss platforms.
CVE-2013-4210 allows remote attackers to perform a denial of service by exhausting file descriptors.
CVE-2013-4210 affects multiple versions including JBoss Enterprise Application Platform 5.0.0 and JBoss SOA Platform 5.3.1.
Yes, CVE-2013-4210 can significantly impact production environments by causing service downtime.