CVE-2010-0738
medium · 5.3Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-05-25Remediation due 2022-06-15
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
5.3
CVSS
79.4%
EPSS (exploit prob.)
100th
EPSS percentile
2010-04-28
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weaknesses
CWE-749
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| redhat | jboss_enterprise_application_platform | 4.2.0 |
| redhat | jboss_enterprise_application_platform | 4.3.0 |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=bugtraq&m=132129312609324&w=2
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35
- http://secunia.com/advisories/39563
- http://securityreason.com/securityalert/8408
- http://securitytracker.com/id?1023918
- http://www.securityfocus.com/bid/39710
- http://www.vupen.com/english/advisories/2010/0992
- https://bugzilla.redhat.com/show_bug.cgi?id=574105
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58147
- https://rhn.redhat.com/errata/RHSA-2010-0376.html
- https://rhn.redhat.com/errata/RHSA-2010-0377.html
- https://rhn.redhat.com/errata/RHSA-2010-0378.html
- https://rhn.redhat.com/errata/RHSA-2010-0379.html
- http://marc.info/?l=bugtraq&m=132129312609324&w=2
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35
- http://secunia.com/advisories/39563
- http://securityreason.com/securityalert/8408
- http://securitytracker.com/id?1023918
- http://www.securityfocus.com/bid/39710
- http://www.vupen.com/english/advisories/2010/0992
- https://bugzilla.redhat.com/show_bug.cgi?id=574105
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58147
- https://rhn.redhat.com/errata/RHSA-2010-0376.html
- https://rhn.redhat.com/errata/RHSA-2010-0377.html
- https://rhn.redhat.com/errata/RHSA-2010-0378.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-0738