Improper access control in JBoss Enterprise Application Platform - CVE-2013-4213

 

Improper access control in JBoss Enterprise Application Platform - CVE-2013-4213

Published: August 16, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42662
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2013-4213
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Red Hat Inc.
Affected software:
JBoss Enterprise Application Platform

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.


How to mitigate CVE-2013-4213

Install update from vendor's website.

Sources