JBoss EAP jmx authentication bypass with crafted HTTP request
Published Apr 28, 2010 ·Due Jun 15, 2022
5.3
MEDIUMCVSS 3.1
EPSS 79.42%
Description
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
Affected products
No data.
- 4.2.0
- 4.3.0
No data.
JBEAP 4.2.0 for RHEL 4
hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
hsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jacorb-0:2.3.0-1jpp.ep1.10.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jboss-aop-0:1.5.5-3.CP05.2.ep1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jboss-cache-0:1.4.1-6.SP14.1.ep1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jboss-remoting-0:2.2.3-3.SP2.ep1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jboss-seam-0:1.2.1-1.ep1.24.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jbossas-0:4.2.0-6.GA_CP09.6.ep1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
rh-eap-docs-0:4.2.0-7.GA_CP09.ep1.5.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 5
hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jacorb-0:2.3.0-1jpp.ep1.10.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jboss-remoting-0:2.2.3-3.SP2.ep1.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jboss-seam-0:1.2.1-1.ep1.24.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jbossas-0:4.2.0-6.GA_CP09.6.ep1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
rh-eap-docs-0:4.2.0-7.GA_CP09.ep1.4.1.el5
Fixed · RHSA-2010:0378
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
hsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jacorb-0:2.3.0-1jpp.ep1.10.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-aop-0:1.5.5-3.CP05.2.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-cache-0:1.4.1-6.SP14.1.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-remoting-0:2.2.3-3.SP2.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-seam2-0:2.0.2.FP-1.ep1.23.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jbossas-0:4.3.0-7.GA_CP08.5.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jbossws-0:2.0.1-5.SP2_CP08.1.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
rh-eap-docs-0:4.3.0-7.GA_CP08.ep1.6.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jacorb-0:2.3.0-1jpp.ep1.10.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-remoting-0:2.2.3-3.SP2.ep1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el5.1
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-seam2-0:2.0.2.FP-1.ep1.23.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jbossas-0:4.3.0-7.GA_CP08.5.ep1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jbossws-0:2.0.1-5.SP2_CP08.1.ep1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
rh-eap-docs-0:4.3.0-7.GA_CP08.ep1.5.el5
Fixed · RHSA-2010:0379
| Product | Package | State | Advisory |
|---|---|---|---|
| JBEAP 4.2.0 for RHEL 4 | hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | hsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jacorb-0:2.3.0-1jpp.ep1.10.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jboss-aop-0:1.5.5-3.CP05.2.ep1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jboss-cache-0:1.4.1-6.SP14.1.ep1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jboss-remoting-0:2.2.3-3.SP2.ep1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jboss-seam-0:1.2.1-1.ep1.24.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jbossas-0:4.2.0-6.GA_CP09.6.ep1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | rh-eap-docs-0:4.2.0-7.GA_CP09.ep1.5.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 5 | hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jacorb-0:2.3.0-1jpp.ep1.10.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jboss-remoting-0:2.2.3-3.SP2.ep1.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jboss-seam-0:1.2.1-1.ep1.24.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jbossas-0:4.2.0-6.GA_CP09.6.ep1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | rh-eap-docs-0:4.2.0-7.GA_CP09.ep1.4.1.el5 | Fixed | RHSA-2010:0378 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | hsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jacorb-0:2.3.0-1jpp.ep1.10.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-aop-0:1.5.5-3.CP05.2.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-cache-0:1.4.1-6.SP14.1.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-remoting-0:2.2.3-3.SP2.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-seam2-0:2.0.2.FP-1.ep1.23.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jbossas-0:4.3.0-7.GA_CP08.5.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jbossws-0:2.0.1-5.SP2_CP08.1.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | rh-eap-docs-0:4.3.0-7.GA_CP08.ep1.6.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jacorb-0:2.3.0-1jpp.ep1.10.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-remoting-0:2.2.3-3.SP2.ep1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el5.1 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-seam2-0:2.0.2.FP-1.ep1.23.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jbossas-0:4.3.0-7.GA_CP08.5.ep1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jbossws-0:2.0.1-5.SP2_CP08.1.ep1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | rh-eap-docs-0:4.3.0-7.GA_CP08.ep1.5.el5 | Fixed | RHSA-2010:0379 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
1 other source (CISA ADP) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Date Added
May 25, 2022
Patch Due
Jun 15, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 14, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 79.42% (0.79415) | 99.59th | v5 (v2026.06.15) |
| Jun 15, 2026 | 79.42% (0.79415) | 99.55th | v5 (v2026.06.15) |
| Jun 5, 2026 | 92.43% (0.92431) | 99.74th | v4 (v2025.03.14) |
| Nov 23, 2025 | 91.29% (0.91288) | 99.63th | v4 (v2025.03.14) |
| Aug 24, 2025 | 92.46% (0.92458) | 99.72th | v4 (v2025.03.14) |
| Jul 25, 2025 | 91.33% (0.91331) | 99.63th | v4 (v2025.03.14) |
| Jun 5, 2025 | 93.03% (0.93025) | 99.77th | v4 (v2025.03.14) |
| Jun 1, 2025 | 91.86% (0.91857) | 99.68th | v4 (v2025.03.14) |
| Mar 17, 2025 | 92.87% (0.92871) | 99.77th | v4 (v2025.03.14) |
| Dec 17, 2024 | 95.03% (0.95027) | 99.49th | v3 (v2023.03.01) |
| Jun 29, 2024 | 96.76% (0.96762) | 99.68th | v3 (v2023.03.01) |
| Jun 15, 2024 | 97.40% (0.97402) | 99.92th | v3 (v2023.03.01) |
| Apr 30, 2024 | 97.35% (0.97353) | 99.89th | v3 (v2023.03.01) |
| Mar 16, 2024 | 97.33% (0.97334) | 99.88th | v3 (v2023.03.01) |
| Feb 1, 2024 | 97.41% (0.97414) | 99.92th | v3 (v2023.03.01) |
| Jun 29, 2023 | 97.43% (0.97429) | 99.89th | v3 (v2023.03.01) |
| May 15, 2023 | 97.41% (0.97410) | 99.87th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.46% (0.97456) | 99.91th | v3 (v2023.03.01) |
| Mar 6, 2023 | 83.25% (0.83245) | 99.59th | v2 (v2022.01.01) |
| Feb 13, 2023 | 83.25% (0.83245) | 99.59th | v2 (v2022.01.01) |
| Feb 3, 2023 | 86.36% (0.86362) | 99.70th | v2 (v2022.01.01) |
| Feb 4, 2022 | 83.25% (0.83245) | 99.51th | v2 (v2022.01.01) |
References (19)
- http://marc.info/?l=bugtraq&m=132129312609324&w=2 vendor-advisoryx_refsource_HPExploitMailing List
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35 x_refsource_CONFIRMThird Party Advisory
- http://secunia.com/advisories/39563 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://securityreason.com/securityalert/8408 third-party-advisoryx_refsource_SREASONBroken Link
- http://securitytracker.com/id?1023918 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/39710 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2010/0992 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- https://access.redhat.com/kb/docs/DOC-30741
- https://access.redhat.com/security/cve/CVE-2010-0738 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=574105 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58147 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2010-0738
- https://rhn.redhat.com/errata/RHSA-2010-0376.html vendor-advisoryx_refsource_REDHATBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0377.html vendor-advisoryx_refsource_REDHATBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0378.html vendor-advisoryx_refsource_REDHATBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0379.html vendor-advisoryx_refsource_REDHATVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0738 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2010-0738
Change history (7)
- CISA ADP
- SSVC automatable changed from yes to
no yes → no
- CVSS severity changed from MEDIUM to
LOW MEDIUM → LOW
- CVSS vector changed from CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N to
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N → CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- CVSS score changed from 5.3 to
3.7 5.3 → 3.7
- SSVC automatable changed from yes to
no
- CISA ADP
- SSVC automatable changed from no to
yes no → yes
- SSVC automatable changed from no to
yes
- CISA ADP
- SSVC automatable changed from yes to
no yes → no
- SSVC automatable changed from yes to
no
- CISA ADP
- SSVC automatable changed from no to
yes no → yes
- SSVC automatable changed from no to
yes