Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 does not check the JON agent key, which allows remote attackers to spoof the identity of arbitrary agents via the registered agent name.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2014-02-14T15:00:00

Updated: 2014-02-14T14:57:01

Reserved: 2011-12-07T00:00:00


Link: CVE-2012-0052

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2014-02-14T15:55:04.750

Modified: 2014-02-14T18:44:12.440


Link: CVE-2012-0052

JSON object: View

cve-icon Redhat Information

No data.

CWE