Improper access control in JBoss Enterprise Application Platform - CVE-2013-4213
Published: August 16, 2013 / Updated: August 11, 2020
Vulnerability identifier: #VU42662
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2013-4213
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Red Hat Inc.
Affected software:
JBoss Enterprise Application Platform
JBoss Enterprise Application Platform
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
How to mitigate CVE-2013-4213
Install update from vendor's website.
Sources
- http://osvdb.org/96216
- http://rhn.redhat.com/errata/RHSA-2013-1151.html
- http://rhn.redhat.com/errata/RHSA-2013-1152.html
- http://rhn.redhat.com/errata/RHSA-2013-1437.html
- http://secunia.com/advisories/54508
- http://www.securitytracker.com/id/1028898
- https://bugzilla.redhat.com/show_bug.cgi?id=985359
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86387