CVE-2010-0738
בינונית 5.3 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Red Hat JBoss Authentication Bypass Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
מדדים
- CVSS 3.1
-
5.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N - EPSS — סבירות ניצול
- 79% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-749
מוצרים מושפעים
redhat: jboss enterprise application platform
קישורים
- http://secunia.com/advisories/39563 Broken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/0992 Broken LinkVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0379.html Vendor Advisory
- http://secunia.com/advisories/39563 Broken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/0992 Broken LinkVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0379.html Vendor Advisory
- http://marc.info/?l=bugtraq&m=132129312609324&w=2 ExploitMailing List
- http://marc.info/?l=bugtraq&m=132129312609324&w=2 ExploitMailing List
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.as… Third Party Advisory
- http://securityreason.com/securityalert/8408 Broken Link