Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2012-4529

EPSS 0.56% · P68
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2012-4529

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The org.apache.catalina.connector.Response.encodeURL method in Red Hat JBoss Web 7.1.x and earlier, when the tracking mode is set to COOKIE, sends the jsessionid in the URL of the first response of a session, which allows remote attackers to obtain the session id (1) via a man-in-the-middle attack or (2) by reading a log.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Red Hat JBoss Web 会话ID信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Red Hat JBoss Web是美国(Red Hat)公司的一款构建在Apache和Tomcat之上的Web服务器,它支持在自定义、轻量级的框架中开发大型网站以及Web应用程序。 Red Hat JBoss Web 7.1.x及之前的版本中的org.apache.catalina.connector.Response.encodeURL方法中存在安全漏洞,该漏洞源于当使用COOKIE会话跟踪方法时,程序在发送会话请求的URL参数中错误的添加jsessionid。远程攻击者可通过实施中间人攻击或读取日志
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2012-4529

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2012-4529

登录查看更多情报信息。

Same Patch Batch · n/a · 2013-10-28 · 28 CVEs total

CVE-2013-4402GnuPG 拒绝服务漏洞
CVE-2013-6285Tyler Technologies TaxWeb 信息泄露漏洞
CVE-2013-6020Tyler Technologies TaxWeb 信息泄露漏洞
CVE-2013-6019Tyler Technologies TaxWeb 跨站脚本漏洞
CVE-2013-6018Tyler Technologies TaxWeb 跨站请求伪造漏洞
CVE-2013-5430IBM Security AppScan Enterprise Jazz Team Server组件信任管理漏洞
CVE-2013-2186Apache Commons FileUpload 输入验证错误漏洞
CVE-2013-2102Red Hat JBoss Portal JGroups Diagnostics Service 信息泄露漏洞
CVE-2013-1056X.Org X Server Xephyr 本地拒绝服务漏洞
CVE-2012-4572Red Hat JBoss JBoss EAP 身份验证安全绕过漏洞
CVE-2013-6289TYPO3 Apache Solr for TYPO3扩展跨站脚本漏洞
CVE-2013-6288TYPO3 Apache Solr for TYPO3扩展安全漏洞
CVE-2013-6012Juniper Junos 未授权访问漏洞
CVE-2013-5744Feng Office ‘index.php’ 跨站脚本漏洞
CVE-2013-6014Juniper Junos 信息泄露漏洞
CVE-2013-4394systemd X Keyboard Extension Processing 本地提权漏洞
CVE-2013-4393systemd ‘journald’功能拒绝服务漏洞
CVE-2013-4392systemd 后置链接漏洞
CVE-2013-4391systemd ‘journald-native.c’远程整数溢出漏洞
CVE-2013-3704libzypp RPM GPG密钥导入和处理功能安全漏洞

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2012-4529

No comments yet


Leave a comment