---
title: "CVE-2012-2377\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2012-2377?format=md
keywords: index, follow
---

# CVE-2012-2377

Publication date 23 November 2012

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

JGroups diagnostics service in JBoss Enterprise Portal Platform before
5.2.2, SOA Platform before 5.3.0, and BRMS Platform before 5.3.0, is
enabled without authentication when started by the JGroups channel, which
allows remote attackers in adjacent networks to read diagnostics
information via a crafted IP multicast.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2012-2377?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| jbossas4 | 12.04 LTS precise | Not affected |
| 11.10 oneiric | Not affected |
| 11.04 natty | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [tyhicks](https://launchpad.net/~tyhicks)

Per Debian, not affected

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2377)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2012-2377)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2012-2377)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2012-2377)

### Other references

* <https://rhn.redhat.com/errata/RHSA-2012-1028.html>
* <https://www.cve.org/CVERecord?id=CVE-2012-2377>
