Vulnerability Name: | CVE-2012-1154 (CCN-76438) | ||||||||
Assigned: | 2012-06-19 | ||||||||
Published: | 2012-06-19 | ||||||||
Updated: | 2012-11-08 | ||||||||
Summary: | mod_cluster 1.0.10 before 1.0.10 CP03 and 1.1.x before 1.1.4, as used in JBoss Enterprise Application Platform 5.1.2, when "ROOT" is set to excludedContexts, exposes the root context of the server, which allows remote attackers to bypass access restrictions and gain access to applications deployed on the root context via unspecified vectors. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-264 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2012-1154 Source: REDHAT Type: UNKNOWN RHSA-2012:1010 Source: REDHAT Type: UNKNOWN RHSA-2012:1011 Source: REDHAT Type: UNKNOWN RHSA-2012:1012 Source: CCN Type: RHSA-2012-1052 Moderate: mod_cluster security update Source: REDHAT Type: UNKNOWN RHSA-2012:1052 Source: REDHAT Type: UNKNOWN RHSA-2012:1053 Source: CCN Type: RHSA-2012-1166 Moderate: mod_cluster security update Source: REDHAT Type: UNKNOWN RHSA-2012:1166 Source: SECUNIA Type: Vendor Advisory 49636 Source: CCN Type: JBoss Web site JBoss Source: CCN Type: OSVDB ID: 83112 JBoss Multiple Products mod_cluster Server Root Context Exposure Access Restriction Bypass Source: CCN Type: BID-54086 JBoss 'mod_cluster' CVE-2012-1154 Security Bypass Vulnerability Source: CCN Type: Red Hat Bugzilla Bug 802200 CVE-2012-1154 mod_cluster registers and exposes the root context of a server by default, despite ROOT being in the excluded-contexts list Source: MISC Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=802200 Source: CONFIRM Type: UNKNOWN https://community.jboss.org/message/624018 Source: XF Type: UNKNOWN jboss-modcluster-sec-bypass(76438) Source: CONFIRM Type: UNKNOWN https://issues.jboss.org/browse/MODCLUSTER-253 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |