jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allows remote attackers to gain privileges as the CS-MARS administrator and execute arbitrary Java code via an invokeOp action in the BSHDeployer jboss.scripts service name.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Security_monitoring_analysis_and_response_system | Cisco | 4.2.0 (including) | 4.2.0 (including) |