Back

MEDIUM KEV Used in ransomware campaigns

JBoss EAP jmx authentication bypass with crafted HTTP request

Published Apr 28, 2010 ·Due Jun 15, 2022

Description

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (19)

Change history (7)
  1. CISA ADP
    • SSVC automatable changed from yes to no
    • CVSS severity changed from MEDIUM to LOW
    • CVSS vector changed from CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N to CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
    • CVSS score changed from 5.3 to 3.7
  2. CISA ADP
    • SSVC automatable changed from no to yes
  3. CISA ADP
    • SSVC automatable changed from yes to no
  4. CISA ADP
    • SSVC automatable changed from no to yes
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 28, 2010
Updated Oct 1, 2026
Reserved Feb 26, 2010
CISA Vulnrichment
Updated Aug 14, 2026
NVD
Status Analyzed
Modified Oct 2, 2026
Red Hat
Severity Critical
Public date Apr 26, 2010