Red Hat JBoss Fuse before 6.2.0 allows remote authenticated users to bypass intended restrictions and access the HawtIO console by leveraging an account defined in the users.properties file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Jboss_fuse | Redhat | * | 6.1.0 (including) |
Red Hat JBoss A-MQ 6.2 | RedHat | * | |
Red Hat JBoss Fuse 6.2 | RedHat | * |