2.6

CVE-2010-3862

The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka JBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Jboss Remoting Version 2.2.0
Redhat ≫ Jboss Remoting Version 2.2.2 Update sp10
Redhat ≫ Jboss Remoting Version 2.2.2 Update sp11
Redhat ≫ Jboss Remoting Version 2.2.2 Update sp2
Redhat ≫ Jboss Remoting Version 2.2.2 Update sp4
Redhat ≫ Jboss Remoting Version 2.2.2 Update sp7
Redhat ≫ Jboss Remoting Version 2.2.2 Update sp8
Redhat ≫ Jboss Remoting Version 2.2.3
Redhat ≫ Jboss Remoting Version 2.2.3 Update sp1
Redhat ≫ Jboss Remoting Version 2.2.3 Update sp2
Redhat ≫ Jboss Remoting Version 2.2.3 Update sp3
Redhat ≫ Jboss Enterprise Application Platform Version 4.3.0 Update cp01
Redhat ≫ Jboss Enterprise Application Platform Version 4.3.0 Update cp02
Redhat ≫ Jboss Enterprise Application Platform Version 4.3.0 Update cp03
Redhat ≫ Jboss Enterprise Application Platform Version 4.3.0 Update cp04
Redhat ≫ Jboss Enterprise Application Platform Version 4.3.0 Update cp05
Redhat ≫ Jboss Enterprise Application Platform Version 4.3.0 Update cp06
Redhat ≫ Jboss Enterprise Application Platform Version 4.3.0 Update cp07
Redhat ≫ Jboss Enterprise Application Platform Version 4.3.0 Update cp08
Redhat ≫ Jboss Enterprise Application Platform Version 4.3.0 Update cp09
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.61% 0.834
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://securitytracker.com/id?1024813
http://www.redhat.com/support/errata/RHSA-2010-0937.html
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0938.html
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0939.html
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0959.html
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0960.html
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0961.html
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0962.html
Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2010-0963.html
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=641389
Patch
https://issues.jboss.org/browse/JBPAPP-5253
https://issues.jboss.org/browse/JBREM-1261