CVE-2013-3734
Last modified
CVE-2013-3734 is a vulnerability of currently unknown severity. The Embedded Jopr component in JBoss Application Server includes the cleartext datasource password in unspecified HTML responses, which might allow (1) man-in-the-middle attackers to obtain sensitive information by leveraging failure to use SSL or (2) attackers to obtain sensitive information by reading the HTML source code. NOTE: the vendor says that this does not cross a trust boundary and that it is recommended best-practice that SSL is configured for the administrative console. EPSS estimates a 1.58% chance of exploitation in the next 30 days.
Description
The Embedded Jopr component in JBoss Application Server includes the cleartext datasource password in unspecified HTML responses, which might allow (1) man-in-the-middle attackers to obtain sensitive information by leveraging failure to use SSL or (2) attackers to obtain sensitive information by reading the HTML source code. NOTE: the vendor says that this does not cross a trust boundary and that it is recommended best-practice that SSL is configured for the administrative console
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Jboss Application Server | <= 1.2 |
References
- http://www.securityfocus.com/bid/60429Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=971637Issue Tracking, Vendor Advisory
- https://www.halock.com/blog/cve-2013-3734-jboss-administration-console-password-returned-response/Issue Tracking, Third Party Advisory
- http://www.securityfocus.com/bid/60429Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=971637Issue Tracking, Vendor Advisory
- https://www.halock.com/blog/cve-2013-3734-jboss-administration-console-password-returned-response/Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-3734?
How severe is CVE-2013-3734?
How do I fix CVE-2013-3734?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2013
- CVE-2013-3724The mk_request_header_process function in mk_request.c in Mo…
- CVE-2013-3725Invision Power Board (IPB) through 3.x allows admin account …9.8
- CVE-2013-3726Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2013-3727SQL injection vulnerability in Kasseler CMS before 2 r1232 a…
- CVE-2013-3728Cross-site scripting (XSS) vulnerability in Kasseler CMS bef…
- CVE-2013-3729Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2013-3735The Zend Engine in PHP before 5.4.16 RC1, and 5.5.0 before R…7.5
- CVE-2013-3736Cross-site scripting (XSS) vulnerability in the MobileUI (ak…
- CVE-2013-3737The MobileUI (aka RT-Extension-MobileUI) extension before 1.…
- CVE-2013-3738A File Inclusion vulnerability exists in Zabbix 2.0.6 due to…9.8
- CVE-2013-3739Directory traversal vulnerability in editor.php in Network W…
- CVE-2013-3742Cross-site scripting (XSS) vulnerability in view_create.php …
Are you affected by CVE-2013-3734?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
