Back

HIGH KEV Used in ransomware campaigns

JBoss Application Server Web Console Authentication bypass

Published Apr 28, 2010 ·Due Jun 15, 2022

Description

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (16)

Change history (7)
  1. CISA ADP
    • SSVC automatable changed from yes to no
    • CVSS severity changed from HIGH to MEDIUM
    • CVSS vector changed from CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N to CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
    • CVSS score changed from 7.5 to 5.9
  2. CISA ADP
    • SSVC automatable changed from no to yes
  3. CISA ADP
    • SSVC automatable changed from yes to no
  4. CISA ADP
    • SSVC automatable changed from no to yes
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 28, 2010
Updated Oct 1, 2026
Reserved Apr 15, 2010
CISA Vulnrichment
Updated Aug 14, 2026
NVD
Status Analyzed
Modified Oct 2, 2026
Red Hat
Severity Low
Public date Apr 26, 2010