CVE-2011-4605
JNDI: unauthenticated remote write access is permitted by default
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The (1) JNDI service, (2) HA-JNDI service, and (3) HAJNDIFactory invoker servlet in JBoss Enterprise Application Platform 4.3.0 CP10 and 5.1.2, Web Platform 5.1.2, SOA Platform 4.2.0.CP05 and 4.3.0.CP05, Portal Platform 4.3 CP07 and 5.2.x before 5.2.2, and BRMS Platform before 5.3.0 do not properly restrict write access, which allows remote attackers to add, delete, or modify items in a JNDI tree via unspecified vectors.
El (1) servicio JNDI, (2) servicio HA-JNDI, y (3) servlet HAJNDIFactory en JBoss Enterprise Application Platform v4.3.0 CP10 y v5.1.2, Web Platform v5.1.2, SOA Platform v4.2.0.CP05 y v4.3.0.CP05, Portal Platform 4.3 CP07 y v5.2.x anterior a v5.2.2, y BRMS Platform anterior v5.3.0 no restringe correctamente el acceso de escritura, permitiendo a atacantes remotos añadir, borrar o modificar elementos en un árbol JNDI mediante vectores desconocidos.
JBoss Application Server is the base package for JBoss Enterprise Application Platform, providing the core server components. The Java Naming and Directory Interface Java API allows Java software clients to locate objects or services in an application server. The Java Authorization Contract for Containers specification defines Permission classes and the binding of container access decisions to operations on instances of these permission classes. JaccAuthorizationRealm performs authorization based on Java ACC permissions and a Policy implementation. It was found that the JBoss JNDI service allowed unauthenticated, remote write access by default. The JNDI and HA-JNDI services, and the HAJNDIFactory invoker servlet were all affected. A remote attacker able to access the JNDI service, HA-JNDI service, or the HAJNDIFactory invoker servlet on a JBoss server could use this flaw to add, delete, and modify items in the JNDI tree. This could have various, application-specific impacts.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-11-29 CVE Reserved
- 2012-06-21 CVE Published
- 2024-08-07 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
- CWE-306: Missing Authentication for Critical Function
CAPEC
References (20)
URL | Tag | Source |
---|---|---|
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=766469 | X_refsource_misc | |
http://www.securityfocus.com/bid/54644 | Vdb Entry | |
http://www.securitytracker.com/id?1027501 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2012-1022.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2012-1023.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2012-1024.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2012-1025.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2012-1026.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2012-1027.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2012-1028.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2012-1109.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2012-1125.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2012-1232.html | 2023-02-13 | |
http://rhn.redhat.com/errata/RHSA-2012-1295.html | 2023-02-13 | |
http://secunia.com/advisories/49656 | 2023-02-13 | |
http://secunia.com/advisories/49658 | 2023-02-13 | |
http://secunia.com/advisories/50084 | 2023-02-13 | |
http://secunia.com/advisories/50549 | 2023-02-13 | |
https://access.redhat.com/security/cve/CVE-2011-4605 | 2012-09-19 | |
https://bugzilla.redhat.com/show_bug.cgi?id=766469 | 2012-09-19 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 4.3.0 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "4.3.0" | cp10 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 5.1.2 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "5.1.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Brms Platform Search vendor "Redhat" for product "Jboss Enterprise Brms Platform" | <= 5.2.0 Search vendor "Redhat" for product "Jboss Enterprise Brms Platform" and version " <= 5.2.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Portal Platform Search vendor "Redhat" for product "Jboss Enterprise Portal Platform" | 4.3.0 Search vendor "Redhat" for product "Jboss Enterprise Portal Platform" and version "4.3.0" | cp07 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Portal Platform Search vendor "Redhat" for product "Jboss Enterprise Portal Platform" | 5.2.0 Search vendor "Redhat" for product "Jboss Enterprise Portal Platform" and version "5.2.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Portal Platform Search vendor "Redhat" for product "Jboss Enterprise Portal Platform" | 5.2.1 Search vendor "Redhat" for product "Jboss Enterprise Portal Platform" and version "5.2.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Soa Platform Search vendor "Redhat" for product "Jboss Enterprise Soa Platform" | 4.2.0 Search vendor "Redhat" for product "Jboss Enterprise Soa Platform" and version "4.2.0" | cp05 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Soa Platform Search vendor "Redhat" for product "Jboss Enterprise Soa Platform" | 4.3.0 Search vendor "Redhat" for product "Jboss Enterprise Soa Platform" and version "4.3.0" | cp05 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Web Platform Search vendor "Redhat" for product "Jboss Enterprise Web Platform" | 5.1.2 Search vendor "Redhat" for product "Jboss Enterprise Web Platform" and version "5.1.2" | - |
Affected
|