Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administrators via certain MBean operations, a different vulnerability than CVE-2006-3733.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
http://osvdb.org/33142 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/32673 | vdb entry |
http://www.securityfocus.com/archive/1/460934/100/0/threaded | mailing list |
http://www.securityfocus.com/archive/1/461004/100/0/threaded | mailing list vendor advisory |