Description
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.
Remediation
References
Related Vulnerabilities
MySQL CVE-2023-22057 Vulnerability (CVE-2023-22057)
Liferay Portal Incorrect Default Permissions Vulnerability (CVE-2021-33334)
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2012-5159)
Ruby Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3655)