CVE detail
CVE-2011-4608 — CVE-2011-4608
Published 2012-01-27 · Modified 2026-06-16 · Vendor redhat · Product jboss_enterprise_application_platform · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0320
EPSS probability
exploitation probability, 30d
87.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
mod_cluster in JBoss Enterprise Application Platform 5.1.2 for Red Hat Linux allows worker nodes to register with arbitrary virtual hosts, which allows remote attackers to bypass intended access restrictions and provide malicious content, hijack sessions, and steal credentials by registering from an external vhost that does not enforce security constraints.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References