CVE-2010-1428
גבוהה 7.5 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Red Hat JBoss Information Disclosure Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS — סבירות ניצול
- 62% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-749
מוצרים מושפעים
redhat: jboss enterprise application platform
קישורים
- http://secunia.com/advisories/39563 Broken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/0992 Broken LinkVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0376.html Broken LinkVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0379.html Vendor Advisory
- http://secunia.com/advisories/39563 Broken LinkVendor Advisory
- http://www.vupen.com/english/advisories/2010/0992 Broken LinkVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0376.html Broken LinkVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0379.html Vendor Advisory
- http://marc.info/?l=bugtraq&m=132698550418872&w=2 ExploitMailing List
- http://marc.info/?l=bugtraq&m=132698550418872&w=2 ExploitMailing List