REDHAT-BUG-983489: Low severity JGroups JGroups vulnerability

Published Jul 11, 2013
·
Updated

A flaw was found in JGroup's DiagnosticsHandler that allowed an attacker on an adjacent network to reuse the credentials from a previous successful authentication. This could be exploited to read diagnostic information (information disclosure) and attain limited remote code execution.

This issue affects JGroups versions 3.0.x (3.0.11.Final and later), 3.1.x (3.1.0.Final and later), 3.2.x (prior to 3.2.10.Final) and 3.3.x (prior to 3.3.3.Final).

Affected Software

1 affected component
JGroups JGroups>=3.0.11.Final, >=3.1.0.Final, <3.2.10.Final, <3.3.3.Final

Event History

Jul 11, 2013
Data Sourced
10:14 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-983489?

The severity of REDHAT-BUG-983489 is considered critical due to its potential for information disclosure and limited remote code execution.

2

How do I fix REDHAT-BUG-983489?

To fix REDHAT-BUG-983489, update JGroups to a version that is not affected by this vulnerability, specifically versions 3.2.10.Final or later.

3

What versions of JGroups are affected by REDHAT-BUG-983489?

REDHAT-BUG-983489 affects JGroups versions from 3.0.11.Final up to but not including 3.3.3.Final.

4

What are the potential impacts of exploiting REDHAT-BUG-983489?

Exploiting REDHAT-BUG-983489 could lead to unauthorized reading of diagnostic information and possible limited remote code execution.

5

Who is vulnerable to REDHAT-BUG-983489?

Systems running the affected versions of JGroups are vulnerable to REDHAT-BUG-983489, particularly those in an adjacent network.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203