Red Hat JBoss Operations Network (JON) before 2.4.2 and 3.0.x before 3.0.1 allows remote attackers to hijack agent sessions via an agent registration request without a security token.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2012-0100
https://bugzilla.redhat.com/show_bug.cgi?id=783008