CVE-2012-2377

low
Published 2012-11-23 · Modified 2026-04-29
CVSS v3
CVSS v2
3.3
VIR risk
3.3

Description

JGroups diagnostics service in JBoss Enterprise Portal Platform before 5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is enabled without authentication when started by the JGroups channel, which allows remote attackers in adjacent networks to read diagnostics information via a crafted IP multicast.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/50549

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/50084

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/49669

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2012-1232.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2012-1125.html

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://rhn.redhat.com/errata/RHSA-2012-1028.html

Application impact

VendorProductVersionsFixed
redhatjboss_enterprise_portal_platform{"endIncluding":"5.2.1"}
redhatjboss_enterprise_portal_platform4.3.0
redhatjboss_enterprise_portal_platform5.0.0
redhatjboss_enterprise_portal_platform5.0.1
redhatjboss_enterprise_portal_platform5.1.0
redhatjboss_enterprise_portal_platform5.1.1
redhatjboss_enterprise_portal_platform5.2.0
redhatjboss_enterprise_soa_platform{"endIncluding":"5.2.0"}
redhatjboss_enterprise_soa_platform4.2.0
redhatjboss_enterprise_soa_platform4.3.0
redhatjboss_enterprise_soa_platform5.0.0
redhatjboss_enterprise_soa_platform5.0.1
redhatjboss_enterprise_soa_platform5.0.2
redhatjboss_enterprise_soa_platform5.1.0
redhatjboss_enterprise_soa_platform5.1.1
redhatjboss_enterprise_brms_platform{"endIncluding":"5.2.0"}

References

CWEs

CWE-287

Verify integrity in audit chain (admin only). AS-IS.