CVE Vulnerabilities

CVE-2010-1428

Published: Apr 28, 2010 | Modified: Oct 22, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
5 LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.

Affected Software

NameVendorStart VersionEnd Version
Jboss_enterprise_application_platformRedhat4.2.0 (including)4.2.0 (including)
Jboss_enterprise_application_platformRedhat4.3.0 (including)4.3.0 (including)
JBEAP 4.2.0 for RHEL 4RedHathibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4*
JBEAP 4.2.0 for RHEL 4RedHathibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHathsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4*
JBEAP 4.2.0 for RHEL 4RedHatjacorb-0:2.3.0-1jpp.ep1.10.el4*
JBEAP 4.2.0 for RHEL 4RedHatjakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4*
JBEAP 4.2.0 for RHEL 4RedHatjboss-aop-0:1.5.5-3.CP05.2.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjbossas-0:4.2.0-6.GA_CP09.6.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjboss-cache-0:1.4.1-6.SP14.1.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjboss-remoting-0:2.2.3-3.SP2.ep1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjboss-seam-0:1.2.1-1.ep1.24.el4*
JBEAP 4.2.0 for RHEL 4RedHatjbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4*
JBEAP 4.2.0 for RHEL 4RedHatjbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4*
JBEAP 4.2.0 for RHEL 4RedHatrh-eap-docs-0:4.2.0-7.GA_CP09.ep1.5.el4*
JBEAP 4.2.0 for RHEL 5RedHathibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5*
JBEAP 4.2.0 for RHEL 5RedHathibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjacorb-0:2.3.0-1jpp.ep1.10.1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjbossas-0:4.2.0-6.GA_CP09.6.ep1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjboss-remoting-0:2.2.3-3.SP2.ep1.1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjboss-seam-0:1.2.1-1.ep1.24.el5*
JBEAP 4.2.0 for RHEL 5RedHatjbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5*
JBEAP 4.2.0 for RHEL 5RedHatjbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5*
JBEAP 4.2.0 for RHEL 5RedHatrh-eap-docs-0:4.2.0-7.GA_CP09.ep1.4.1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHathibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHathibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHathsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjacorb-0:2.3.0-1jpp.ep1.10.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjboss-aop-0:1.5.5-3.CP05.2.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjbossas-0:4.3.0-7.GA_CP08.5.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjboss-cache-0:1.4.1-6.SP14.1.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjboss-remoting-0:2.2.3-3.SP2.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjboss-seam2-0:2.0.2.FP-1.ep1.23.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatjbossws-0:2.0.1-5.SP2_CP08.1.ep1.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4RedHatrh-eap-docs-0:4.3.0-7.GA_CP08.ep1.6.el4*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHathibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHathibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjacorb-0:2.3.0-1jpp.ep1.10.1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjbossas-0:4.3.0-7.GA_CP08.5.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjboss-remoting-0:2.2.3-3.SP2.ep1.1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el5.1*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjboss-seam2-0:2.0.2.FP-1.ep1.23.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatjbossws-0:2.0.1-5.SP2_CP08.1.ep1.1.el5*
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5RedHatrh-eap-docs-0:4.3.0-7.GA_CP08.ep1.5.el5*

References