CVE-2010-0738 KEV EXPLOIT
5.3
MEDIUM · CVSS 3.1 · EPSS 79.4% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-15.
Description
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
Scoring
| CVSS | 5.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| EPSS | 79.42% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-749 |
| On CISA KEV | yes — remediate by 2022-06-15 |
| Public exploit | yes |
| Published | 2010-04-28 |
| Last modified | 2026-08-14 |
CISA KEV
| Name | Red Hat JBoss Authentication Bypass Vulnerability |
|---|---|
| Added | 2022-05-25 |
| Due | 2022-06-15 |
| Vendor / product | Red Hat / JBoss |
| Ransomware use | known |
Affected (1)
| Vendor | Product |
|---|---|
| redhat | jboss enterprise application platform |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | JBoss & JMX Console - Misconfigured Deployment Scanner | 2011-10-03 |
| exploit-db | JBoss Application Server 4.2 < 4.2.0.CP09 / 4.3 < 4.3.0.CP08 - Remote Command Execution | 2011-03-04 |
| exploit-db | JBoss JMX - Console Beanshell Deployer WAR Upload and Deployment (Metasploit) | 2011-01-10 |
| exploit-db | JBoss - Java Class DeploymentFileRepository WAR Deployment (Metasploit) | 2010-08-03 |
References
- http://marc.info/?l=bugtraq&m=132129312609324&w=2
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35
- http://secunia.com/advisories/39563
- http://securityreason.com/securityalert/8408
- http://securitytracker.com/id?1023918
- http://www.securityfocus.com/bid/39710
- http://www.vupen.com/english/advisories/2010/0992
- https://bugzilla.redhat.com/show_bug.cgi?id=574105
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58147
- https://rhn.redhat.com/errata/RHSA-2010-0376.html
- https://rhn.redhat.com/errata/RHSA-2010-0377.html
- https://rhn.redhat.com/errata/RHSA-2010-0378.html
- https://rhn.redhat.com/errata/RHSA-2010-0379.html
- http://marc.info/?l=bugtraq&m=132129312609324&w=2
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35
- http://secunia.com/advisories/39563
- http://securityreason.com/securityalert/8408
- http://securitytracker.com/id?1023918
- http://www.securityfocus.com/bid/39710
- http://www.vupen.com/english/advisories/2010/0992
→ the Explorer · watch your stack · NVD