HackerFeeds
All CVEs

CVE-2010-1428

HIGH7.5
CISA KEV

Published 2010-04-28 · Updated 2026-08-14 · Source secalert@redhat.com

Description

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CWE-749

CISA Known-Exploited Vulnerability

Product: Red HatJBoss

Name: Red Hat JBoss Information Disclosure Vulnerability

Date added: 2022-05-25 · Due: 2022-06-15

USED IN RANSOMWARE

Required action: Apply updates per vendor instructions.

View on NVD