Release date:
Updated on:
Affected Systems:
JBoss Group JBoss Enterprise Application Platform 5.1.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54915
Cve id: CVE-2011-2908
JBoss Enterprise Application Platform (EAP) is a middleware Platform for J2EE applications.
JBoss Enterprise Application Platform 5.1.1 and other versions have the Cross-Site Request Forgery Vulnerability, which allows remote attackers to execute some unauthorized operations and access the affected applications.
<* Source: David Jorm
Link: http://www.redhat.com/products/jbossenterprisemiddleware/application-platform/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
JBoss Group
-----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.jboss.org/