← All CVEs

CVE-2010-0738

medium · 5.3Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-05-25Remediation due 2022-06-15

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

5.3
CVSS
79.4%
EPSS (exploit prob.)
100th
EPSS percentile
2010-04-28
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Weaknesses

CWE-749

Affected products

VendorProductAffected versions
redhatjboss_enterprise_application_platform4.2.0
redhatjboss_enterprise_application_platform4.3.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-0738