CVE-2011-4573
Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote authenticated users when deleting a plug-in configuration update from the group connection properties history, which prevents such activities from being recorded in the audit trail.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0013 (0.1%)
Percentile: 31.9%
EPSS: 2026-05-06
Affects
redhat:jboss_operations_networkTechnical description
Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote authenticated users when deleting a plug-in configuration update from the group connection properties history, which prevents such activities from being recorded in the audit trail.
Published: 4/1/2014, 6:35:52 AM
Last modified: 5/6/2026, 10:30:45 PM