CVE-2013-4128

Publication date

2013-08-16 16:00:00

Family

redhat

State

PUBLISHED

Description

Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by remote-naming, which allows remote attackers to hijack sessions by using a remoting client.