It was found that JGroups did not require necessary headers...
Vulnerability Description
It was found that JGroups did not require necessary headers for encrypt and auth protocols from new nodes joining the cluster. An attacker could use this flaw to bypass security restrictions, and use this vulnerability to send and receive messages within the cluster, leading to information disclosure, message spoofing, or further possible attacks.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-2141
Credits & Attribution
No credits recorded in the NVD database.
References
- https://access.redhat.com/errata/RHSA-2016:1347
- http://rhn.redhat.com/errata/RHSA-2016-2035.html
- https://access.redhat.com/errata/RHSA-2016:1389
- https://access.redhat.com/errata/RHSA-2016:1345
- https://access.redhat.com/errata/RHSA-2016:1376
- https://rhn.redhat.com/errata/RHSA-2016-1330.html
- http://rhn.redhat.com/errata/RHSA-2016-1439.html
- https://rhn.redhat.com/errata/RHSA-2016-1331.html
- http://www.securityfocus.com/bid/91481
- https://access.redhat.com/errata/RHSA-2016:1434
- https://rhn.redhat.com/errata/RHSA-2016-1328.html
- https://access.redhat.com/errata/RHSA-2016:1433
- https://issues.jboss.org/browse/JGRP-2021
- https://access.redhat.com/errata/RHSA-2016:1374
- https://access.redhat.com/errata/RHSA-2016:1432
- https://access.redhat.com/errata/RHSA-2016:1346
- https://rhn.redhat.com/errata/RHSA-2016-1334.html
- https://rhn.redhat.com/errata/RHSA-2016-1333.html
- https://rhn.redhat.com/errata/RHSA-2016-1329.html
- https://rhn.redhat.com/errata/RHSA-2016-1332.html
- http://rhn.redhat.com/errata/RHSA-2016-1435.html
- http://www.securitytracker.com/id/1036165
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://lists.apache.org/thread.html/ra18cac97416abc2958db0b107877c31da28d884fa6e70fd89c87384a%40%3Cdev.geode.apache.org%3E
- https://lists.apache.org/thread.html/rb37cc937d4fc026fb56de4b4ec0d054aa4083c1a4edd0d8360c068a0%40%3Cdev.geode.apache.org%3E
More from redhat
View All →Affected Vendor
redhat
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.