Rapid7 Vulnerability & Exploit Database

Red Hat JBoss: CVE-2011-4608: A remote attacker could intercept credentials and hijack user sessions

Back to Search

Red Hat JBoss: CVE-2011-4608: A remote attacker could intercept credentials and hijack user sessions

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
01/27/2012
Created
07/25/2018
Added
08/01/2017
Modified
08/01/2017

Description

mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide malicious content, hijack sessions, and steal credentials by registering from an external vhost that does not enforce security constraints.

Solution(s)

  • jboss_enterprise_application_platform-cve-2011-4608-1

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;