CVE-2011-3609
Published Nov 26, 2019
Last updated 2 years ago
Overview
- Description
- A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a specially-crafted web page provided by a remote attacker.
- Source
- secalert@redhat.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-352
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:redhat:jboss_application_server:7.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F239FDAE-4DA4-4F60-BD6F-FBFA48836690" }, { "criteria": "cpe:2.3:a:redhat:jboss_application_server:7.0.0:alpha1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "481E63A2-DB87-4BA5-8AA5-04CB765EB203" }, { "criteria": "cpe:2.3:a:redhat:jboss_application_server:7.0.0:beta1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6819992D-FB7D-4E07-91AD-8C25A8666E4A" }, { "criteria": "cpe:2.3:a:redhat:jboss_application_server:7.0.0:beta2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "46594B25-73C0-4D03-BD52-3F97BC2EB72D" }, { "criteria": "cpe:2.3:a:redhat:jboss_application_server:7.0.0:beta3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D8E9DC45-A43B-47BD-B819-A017CD28F20B" }, { "criteria": "cpe:2.3:a:redhat:jboss_application_server:7.0.0:cr1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0966EA02-E802-48BC-A8A9-D0712921A56D" }, { "criteria": "cpe:2.3:a:redhat:jboss_application_server:7.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8BC0CB87-8FCD-4E20-935F-71E8206656F1" }, { "criteria": "cpe:2.3:a:redhat:jboss_application_server:7.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CE04DE7-01AC-4C55-B5F4-1A5F39132FBC" } ], "operator": "OR" } ] } ]