2.6
CVE-2010-3862
- EPSS 1.39%
- Veröffentlicht 30.12.2010 21:00:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka JBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Jboss Remoting Version2.2.0
Redhat ≫ Jboss Remoting Version2.2.2 Updatesp10
Redhat ≫ Jboss Remoting Version2.2.2 Updatesp11
Redhat ≫ Jboss Remoting Version2.2.2 Updatesp2
Redhat ≫ Jboss Remoting Version2.2.2 Updatesp4
Redhat ≫ Jboss Remoting Version2.2.2 Updatesp7
Redhat ≫ Jboss Remoting Version2.2.2 Updatesp8
Redhat ≫ Jboss Remoting Version2.2.3
Redhat ≫ Jboss Remoting Version2.2.3 Updatesp1
Redhat ≫ Jboss Remoting Version2.2.3 Updatesp2
Redhat ≫ Jboss Remoting Version2.2.3 Updatesp3
Redhat ≫ Jboss Enterprise Application Platform Version4.3.0
Redhat ≫ Jboss Enterprise Application Platform Version4.3.0 Updatecp01
Redhat ≫ Jboss Enterprise Application Platform Version4.3.0 Updatecp02
Redhat ≫ Jboss Enterprise Application Platform Version4.3.0 Updatecp03
Redhat ≫ Jboss Enterprise Application Platform Version4.3.0 Updatecp04
Redhat ≫ Jboss Enterprise Application Platform Version4.3.0 Updatecp05
Redhat ≫ Jboss Enterprise Application Platform Version4.3.0 Updatecp06
Redhat ≫ Jboss Enterprise Application Platform Version4.3.0 Updatecp07
Redhat ≫ Jboss Enterprise Application Platform Version4.3.0 Updatecp08
Redhat ≫ Jboss Enterprise Application Platform Version4.3.0 Updatecp09
Redhat ≫ Jboss Enterprise Application Platform Version5.1.0
Redhat ≫ Jboss Enterprise Web Platform Version5.1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.39% | 0.786 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.