Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
References
Link | Resource |
---|---|
http://rhn.redhat.com/errata/RHSA-2013-1152.html | Vendor Advisory |
http://secunia.com/advisories/54508 | |
http://rhn.redhat.com/errata/RHSA-2013-1151.html | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=985359 | Issue Tracking |
http://www.securitytracker.com/id/1028898 | Third Party Advisory VDB Entry |
http://osvdb.org/96216 | |
http://rhn.redhat.com/errata/RHSA-2013-1437.html | Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/86387 |
Configurations
Information
Published : 2013-08-16 09:55
Updated : 2017-08-28 18:33
NVD link : CVE-2013-4213
Mitre link : CVE-2013-4213
JSON object : View
CWE
CWE-284
Improper Access Control
Products Affected
redhat
- jboss_enterprise_application_platform