6.5

CVE-2011-3609

A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a specially-crafted web page provided by a remote attacker.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
RedhatJboss Application Server Version7.0.0
RedhatJboss Application Server Version7.0.0 Updatealpha1
RedhatJboss Application Server Version7.0.0 Updatebeta1
RedhatJboss Application Server Version7.0.0 Updatebeta2
RedhatJboss Application Server Version7.0.0 Updatebeta3
RedhatJboss Application Server Version7.0.0 Updatecr1
RedhatJboss Application Server Version7.0.1
RedhatJboss Application Server Version7.0.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.637
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.