The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service. AV:A per https://bugzilla.redhat.com/show_bug.cgi?id963984
Publication date: Tue, 29 Oct 2013 02:55:00 +0000