CVE Vulnerabilities

CVE-2010-0738

Published: Apr 28, 2010 | Modified: Jun 28, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
7.5 CRITICAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this applications GET handler by using a different method.

Affected Software

Name Vendor Start Version End Version
Jboss_enterprise_application_platform Redhat 4.2.0 (including) 4.2.0 (including)
Jboss_enterprise_application_platform Redhat 4.3.0 (including) 4.3.0 (including)
JBEAP 4.2.0 for RHEL 4 RedHat hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat hsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jacorb-0:2.3.0-1jpp.ep1.10.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-aop-0:1.5.5-3.CP05.2.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jbossas-0:4.2.0-6.GA_CP09.6.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-cache-0:1.4.1-6.SP14.1.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-remoting-0:2.2.3-3.SP2.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-seam-0:1.2.1-1.ep1.24.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat rh-eap-docs-0:4.2.0-7.GA_CP09.ep1.5.el4 *
JBEAP 4.2.0 for RHEL 5 RedHat hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jacorb-0:2.3.0-1jpp.ep1.10.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jbossas-0:4.2.0-6.GA_CP09.6.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-remoting-0:2.2.3-3.SP2.ep1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-seam-0:1.2.1-1.ep1.24.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat rh-eap-docs-0:4.2.0-7.GA_CP09.ep1.4.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat hsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jacorb-0:2.3.0-1jpp.ep1.10.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-aop-0:1.5.5-3.CP05.2.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossas-0:4.3.0-7.GA_CP08.5.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-cache-0:1.4.1-6.SP14.1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-remoting-0:2.2.3-3.SP2.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-seam2-0:2.0.2.FP-1.ep1.23.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossws-0:2.0.1-5.SP2_CP08.1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat rh-eap-docs-0:4.3.0-7.GA_CP08.ep1.6.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jacorb-0:2.3.0-1jpp.ep1.10.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossas-0:4.3.0-7.GA_CP08.5.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-remoting-0:2.2.3-3.SP2.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el5.1 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-seam2-0:2.0.2.FP-1.ep1.23.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossws-0:2.0.1-5.SP2_CP08.1.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat rh-eap-docs-0:4.3.0-7.GA_CP08.ep1.5.el5 *

References