CVE-2009-4843

ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attackers to execute arbitrary commands via requests to (1) the JMX Management Console or (2) the Web Console.
Configurations

Configuration 1 (hide)

cpe:2.3:a:toutvirtual:virtualiq:3.5:-:pro:*:*:*:*:*

History

21 Nov 2024, 01:10

Type Values Removed Values Added
References () http://secunia.com/advisories/37297 - Vendor Advisory () http://secunia.com/advisories/37297 - Vendor Advisory
References () http://www.securenetwork.it/ricerca/advisory/download/SN-2009-02.txt - Exploit () http://www.securenetwork.it/ricerca/advisory/download/SN-2009-02.txt - Exploit
References () http://www.securityfocus.com/archive/1/507729/100/0/threaded - () http://www.securityfocus.com/archive/1/507729/100/0/threaded -

Information

Published : 2010-05-07 18:24

Updated : 2024-11-21 01:10


NVD link : CVE-2009-4843

Mitre link : CVE-2009-4843

CVE.ORG link : CVE-2009-4843


JSON object : View

Products Affected

toutvirtual

  • virtualiq
CWE
CWE-287

Improper Authentication