Vulnerability Name:

CVE-2013-4210 (CCN-87731)

Assigned:2013-09-30
Published:2013-09-30
Updated:2013-10-31
Summary:The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other products allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2013-4210

Source: REDHAT
Type: UNKNOWN
RHSA-2013:1369

Source: REDHAT
Type: UNKNOWN
RHSA-2013:1370

Source: REDHAT
Type: Vendor Advisory
RHSA-2013:1371

Source: REDHAT
Type: Vendor Advisory
RHSA-2013:1372

Source: REDHAT
Type: Vendor Advisory
RHSA-2013:1373

Source: REDHAT
Type: Vendor Advisory
RHSA-2013:1374

Source: REDHAT
Type: UNKNOWN
RHSA-2013:1448

Source: CCN
Type: JBoss Web site
Red Hat | Red Hat JBoss Middleware

Source: CCN
Type: BID-62721
Red Hat JBoss Remoting CVE-2013-4210 Remote Denial of Service Vulnerability

Source: CCN
Type: Red Hat Bugzilla Bug 994321
(CVE-2013-4210) CVE-2013-4210 JBoss Remoting: DoS by file descriptor exhaustion

Source: XF
Type: UNKNOWN
jbossremoting-cve20134210-dos(87731)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:redhat:jboss_enterprise_application_platform:5.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:jboss_enterprise_brms_platform:5.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:jboss_enterprise_brms_platform:5.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:jboss_enterprise_soa_platform:5.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:jboss_enterprise_soa_platform:5.3.1:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:jboss_enterprise_web_platform:5.2.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:redhat:jboss_enterprise_application_platform:5.2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    redhat jboss enterprise application platform 5.0.0
    redhat jboss enterprise brms platform 5.2.0
    redhat jboss enterprise brms platform 5.3.0
    redhat jboss enterprise soa platform 5.3.0
    redhat jboss enterprise soa platform 5.3.1
    redhat jboss enterprise web platform 5.2.0
    redhat jboss enterprise application platform 5.2.0