Vulnerabilities > Redhat > Jboss Enterprise Portal Platform > 6.0.0

DATE CVE VULNERABILITY TITLE RISK
2013-10-28 CVE-2013-2186 Improper Input Validation vulnerability in multiple products
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
network
low complexity
redhat ubuntu CWE-20
7.5
2013-10-28 CVE-2013-2102 Improper Authentication vulnerability in Redhat Jboss Enterprise Portal Platform
The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.
low complexity
redhat CWE-287
3.3
2013-10-28 CVE-2012-4572 Permissions, Privileges, and Access Controls vulnerability in Redhat products
Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.
local
high complexity
redhat CWE-264
3.7