Vulnerability Name: | CVE-2013-4213 (CCN-86387) | ||||||||
Assigned: | 2013-08-12 | ||||||||
Published: | 2013-08-12 | ||||||||
Updated: | 2017-08-29 | ||||||||
Summary: | Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N) 4.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-284 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-4213 Source: OSVDB Type: UNKNOWN 96216 Source: REDHAT Type: Vendor Advisory RHSA-2013:1151 Source: REDHAT Type: Vendor Advisory RHSA-2013:1152 Source: REDHAT Type: Vendor Advisory RHSA-2013:1437 Source: SECUNIA Type: UNKNOWN 54508 Source: CCN Type: BID-61742 Red Hat JBoss Enterprise Application Platform CVE-2013-4213 Session Fixation Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1028898 Source: CCN Type: Red Hat Bugzilla Bug 985359 CVE-2013-4213 JBoss ejb-client: Session fixation due improper connection caching Source: CONFIRM Type: Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=985359 Source: XF Type: UNKNOWN eap-cve20134213-session-hijacking(86387) Source: XF Type: UNKNOWN eap-cve20134213-session-hijacking(86387) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-4213 | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |