CVE Vulnerabilities

CVE-2010-1428

Published: Apr 28, 2010 | Modified: Jun 28, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
5 LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.

Affected Software

Name Vendor Start Version End Version
Jboss_enterprise_application_platform Redhat 4.2.0 (including) 4.2.0 (including)
Jboss_enterprise_application_platform Redhat 4.3.0 (including) 4.3.0 (including)
JBEAP 4.2.0 for RHEL 4 RedHat hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat hsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jacorb-0:2.3.0-1jpp.ep1.10.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-aop-0:1.5.5-3.CP05.2.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jbossas-0:4.2.0-6.GA_CP09.6.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-cache-0:1.4.1-6.SP14.1.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-remoting-0:2.2.3-3.SP2.ep1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jboss-seam-0:1.2.1-1.ep1.24.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4 *
JBEAP 4.2.0 for RHEL 4 RedHat rh-eap-docs-0:4.2.0-7.GA_CP09.ep1.5.el4 *
JBEAP 4.2.0 for RHEL 5 RedHat hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jacorb-0:2.3.0-1jpp.ep1.10.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jbossas-0:4.2.0-6.GA_CP09.6.ep1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-remoting-0:2.2.3-3.SP2.ep1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jboss-seam-0:1.2.1-1.ep1.24.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5 *
JBEAP 4.2.0 for RHEL 5 RedHat rh-eap-docs-0:4.2.0-7.GA_CP09.ep1.4.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat hsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jacorb-0:2.3.0-1jpp.ep1.10.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-aop-0:1.5.5-3.CP05.2.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossas-0:4.3.0-7.GA_CP08.5.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-cache-0:1.4.1-6.SP14.1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-remoting-0:2.2.3-3.SP2.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jboss-seam2-0:2.0.2.FP-1.ep1.23.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat jbossws-0:2.0.1-5.SP2_CP08.1.ep1.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 RedHat rh-eap-docs-0:4.3.0-7.GA_CP08.ep1.6.el4 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jacorb-0:2.3.0-1jpp.ep1.10.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossas-0:4.3.0-7.GA_CP08.5.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-remoting-0:2.2.3-3.SP2.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el5.1 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jboss-seam2-0:2.0.2.FP-1.ep1.23.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat jbossws-0:2.0.1-5.SP2_CP08.1.ep1.1.el5 *
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 RedHat rh-eap-docs-0:4.3.0-7.GA_CP08.ep1.5.el5 *

References