VYPR
Medium severity6.5NVD Advisory· Published Nov 26, 2019· Updated Jun 16, 2026

CVE-2011-3609

CVE-2011-3609

Description

A CSRF issue was found in JBoss Application Server 7 before 7.1.0. JBoss did not properly restrict access to the management console information (for example via the "Access-Control-Allow-Origin" HTTP access control flag). This can lead to unauthorized information leak if a user with admin privileges visits a specially-crafted web page provided by a remote attacker.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • cpe:2.3:a:redhat:jboss_application_server:7.0.0:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:a:redhat:jboss_application_server:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_application_server:7.0.0:alpha1:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_application_server:7.0.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_application_server:7.0.0:beta2:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_application_server:7.0.0:beta3:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_application_server:7.0.0:cr1:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_application_server:7.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_application_server:7.0.2:*:*:*:*:*:*:*
  • Range: <7.1.0
  • JBoss Application Server/JBoss Application Serverv5
    Range: 7 before 7.1.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.