CVE-2010-1428
high-risk
Published 2010-04-28
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.
Do I need to act?
!
67.6% chance of exploitation in next 30 days
EPSS score — higher than 32% of all CVEs
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ LOW complexity
Affected Products (2)
Affected Vendors
References (23)
Broken Link
http://secunia.com/advisories/39563
Broken Link
http://securitytracker.com/id?1023917
Broken Link
http://www.securityfocus.com/bid/39710
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=585899
Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/58148
Vendor Advisory
https://rhn.redhat.com/errata/RHSA-2010-0379.html
Broken Link
http://secunia.com/advisories/39563
Broken Link
http://securitytracker.com/id?1023917
Broken Link
http://www.securityfocus.com/bid/39710
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=585899
Third Party Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/58148
and 3 more references
59
/ 100
high-risk
Severity
26/34 · High
Exploitability
26/34 · High
Exposure
7/34 · Low