Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://rhn.redhat.com/errata/RHSA-2012-0089.html | vendor advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=783008 | |
http://rhn.redhat.com/errata/RHSA-2012-0406.html | vendor advisory |