Description
Cumin in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0 records broker authentication credentials in a log file, which allows local users to bypass authentication and perform unauthorized actions on jobs and message queues via a direct connection to the broker.
Affected products
- RedHat / enterprise_mrg2.0 – 2.0
References
- MISChttp://www.securitytracker.com/id?1026021
- VENDOR_ADVISORYhttp://secunia.com/advisories/45928
- MISChttp://www.securityfocus.com/bid/49500
- MISChttp://osvdb.org/75217
- VENDOR_ADVISORYhttp://secunia.com/advisories/45887
- MISChttp://www.redhat.com/support/errata/RHSA-2011-1250.html
- MISChttps://bugzilla.redhat.com/show_bug.cgi?id=731574
- MISChttp://www.redhat.com/support/errata/RHSA-2011-1249.html
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/69659