All CVEs View on NVD
CVE-2010-0738
MEDIUM5.3
CISA KEV
Published 2010-04-28 · Updated 2026-08-14 · Source secalert@redhat.com
Description
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-749
CISA Known-Exploited Vulnerability
Product: Red Hat — JBoss
Name: Red Hat JBoss Authentication Bypass Vulnerability
Date added: 2022-05-25 · Due: 2022-06-15
USED IN RANSOMWARE
Required action: Apply updates per vendor instructions.
References
- http://marc.info/?l=bugtraq&m=132129312609324&w=2
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35
- http://secunia.com/advisories/39563
- http://securityreason.com/securityalert/8408
- http://securitytracker.com/id?1023918
- http://www.securityfocus.com/bid/39710
- http://www.vupen.com/english/advisories/2010/0992
- https://bugzilla.redhat.com/show_bug.cgi?id=574105

