Back

CRITICAL

JON: The agent/server communication deserializes data, and does not require authentication

Published Aug 2, 2016

Description

The server in Red Hat JBoss Operations Network (JON) before 3.3.6 allows remote attackers to execute arbitrary code via a crafted HTTP request, related to message deserialization.

Affected products

Remediation

Red Hat statement

It is not feasible to correct this issue with a code change as client SSL certificates need to be created in order to support client authentication. The installation documentation notes how to mitigate this through the creation of certificates to support SSL authentication. This mitigation is the best way to correct this issue and, as a result, we will not be releasing any patches to correct the issue.

Red Hat mitigation

Apply the configuration changes described in the documentation here: https://access.redhat.com/documentation/en-US/Red_Hat_JBoss_Operations_Network/3.3/html/Admin_and_Config/JBoss_ON_and_SSL-Authentication.html For more information, refer to https://access.redhat.com/articles/2570101.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 2, 2016
Updated Aug 6, 2024
Reserved Mar 30, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Critical
Public date May 6, 2016