CVE Vulnerabilities

CVE-2011-4605

Published: Nov 23, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
7.5 IMPORTANT
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2.2, and BRMS Platform before 5.3.0 do not properly restrict write access, which allows remote attackers to add, delete, or modify items in a JNDI tree via unspecified vectors.

Affected Software

NameVendorStart VersionEnd Version
Jboss_enterprise_application_platformRedhat4.3.0-cp10 (including)4.3.0-cp10 (including)
Jboss_enterprise_application_platformRedhat5.1.2 (including)5.1.2 (including)
Jboss_enterprise_brms_platformRedhat*5.2.0 (including)
Jboss_enterprise_portal_platformRedhat4.3.0-cp07 (including)4.3.0-cp07 (including)
Jboss_enterprise_portal_platformRedhat5.2.0 (including)5.2.0 (including)
Jboss_enterprise_portal_platformRedhat5.2.1 (including)5.2.1 (including)
Jboss_enterprise_soa_platformRedhat4.2.0-cp05 (including)4.2.0-cp05 (including)
Jboss_enterprise_soa_platformRedhat4.3.0-cp05 (including)4.3.0-cp05 (including)
Jboss_enterprise_web_platformRedhat5.1.2 (including)5.1.2 (including)
JBEWP 5 for RHEL 5RedHatjbossas-web-0:5.1.2-10.ep5.el5*
JBEWP 5 for RHEL 5RedHatjboss-naming-0:5.0.3-4.CP01_patch_01.1.ep5.el5*
JBEWP 5 for RHEL 6RedHatjbossas-web-0:5.1.2-10.ep5.el6*
JBEWP 5 for RHEL 6RedHatjboss-naming-0:5.0.3-4.CP01_patch_01.2.ep5.el6*
JBoss Enterprise BRMS Platform 5.3RedHat*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjbossas-0:4.3.0-10.GA_CP10_patch_01.1.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjbossas-0:4.3.0-10.GA_CP10_patch_01.1.ep1.el5*
Red Hat JBoss Enterprise Application Platform 5.1RedHat*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4RedHatjbossas-0:5.1.2-10.ep5.el4*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 4RedHatjboss-naming-0:5.0.3-4.CP01_patch_01.1.ep5.el4*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5RedHatjbossas-0:5.1.2-10.ep5.el5*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 5RedHatjboss-naming-0:5.0.3-4.CP01_patch_01.1.ep5.el5*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6RedHatjbossas-0:5.1.2-10.ep5.el6*
Red Hat JBoss Enterprise Application Platform 5 for RHEL 6RedHatjboss-naming-0:5.0.3-4.CP01_patch_01.2.ep5.el6*
Red Hat JBoss Portal 4.3RedHat*
Red Hat JBoss Portal 4.3RedHat*
Red Hat JBoss Portal 5.2RedHat*
Red Hat JBoss SOA Platform 4.2RedHat*
Red Hat JBoss SOA Platform 5.3RedHat*
Red Hat JBoss Web Platform 5.1RedHat*
Jbossas4Ubuntuhardy*
Jbossas4Ubuntulucid*
Jbossas4Ubuntunatty*
Jbossas4Ubuntuoneiric*
Jbossas4Ubuntuprecise*
Jbossas4Ubuntuquantal*
Jbossas4Ubunturaring*
Jbossas4Ubuntusaucy*
Jbossas4Ubuntutrusty*
Jbossas4Ubuntuutopic*

References