描述
The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL loading of Java MBeans, which allows remote attackers to execute arbitrary Java code by registering MBeans.
AI分析AI驱动
受影响产品
aternityaternity
参考资料
- http://www.kb.cert.org/vuls/id/706359Third Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/93208
- http://www.kb.cert.org/vuls/id/706359Third Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/93208