Release date: 2011-11-17
Updated on: 2011-12-13
Affected Systems:
RedHat JBoss EAP 5.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 50720
Cve id: CVE-2011-4085
JBoss Enterprise Application Platform (EAP) is a middleware Platform for J2EE applications.
JBoss Enterprise Application Platform has a security vulnerability in the implementation of calling programs. Attackers can exploit this vulnerability to bypass the authentication mechanism and illegally access the affected applications.
<* Source: David Jorm
Link: https://rhn.redhat.com/errata/RHSA-2011-1805.html
Https://rhn.redhat.com/errata/RHSA-2011-1456.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
RedHat
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.jboss.org/