CVE-2013-2102

Published Oct 28, 2013

Last updated a month ago

Overview

Description
The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.
Source
secalert@redhat.com
NVD status
Deferred

Risk scores

CVSS 2.0

Type
Primary
Base score
3.3
Impact score
2.9
Exploitability score
6.5
Vector string
AV:A/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

nvd@nist.gov
CWE-287

Social media

Hype score
Not currently trending

Evaluator

Comment
AV:A per https://bugzilla.redhat.com/show_bug.cgi?id=963984
Impact
-
Solution
-

Configurations