CVE-2012-4599
Published Aug 22, 2012
Last updated 8 years ago
Overview
- Description
- McAfee SmartFilter Administration, and SmartFilter Administration Bess Edition, before 4.2.1.01 does not require authentication for access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to execute arbitrary code via a crafted .war file.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-287
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:mcafee:smartfilter_administration:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39E48E7D-BB4E-4CF4-BA56-A7B41FDB274A", "versionEndIncluding": "4.2.1" }, { "criteria": "cpe:2.3:a:mcafee:smartfilter_administration:*:*:bess:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0AC5A81D-5D22-4ABD-A4F0-62BF709C330A", "versionEndIncluding": "4.2.1" } ], "operator": "OR" } ] } ]