Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat JBoss Portal JGroups Diagnostics Service 信息泄露漏洞
Vulnerability Description
Red Hat JBoss Portal是美国红帽(Red Hat)公司的一套开源且符合标准的门户平台。该平台可搭建、布局一个门户网站的Web界面,用于发布、管理内容以及定制用户体验。 Red Hat JBoss Portal 6.1.0之前的版本中的默认配置中存在安全漏洞,该漏洞源于当使用JGroups channel时,JGroups诊断服务没有启用身份验证。远程攻击者可通过访问服务利用该楼的获取诊断信息。
CVSS Information
N/A
Vulnerability Type
N/A