JBoss Application Server Web Console Authentication bypass
Published Apr 28, 2010 ·Due Jun 15, 2022
7.5
HIGHCVSS 3.1
EPSS 61.49%
Description
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.
Affected products
No data.
- 4.2.0
- 4.3.0
No data.
JBEAP 4.2.0 for RHEL 4
hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
hsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jacorb-0:2.3.0-1jpp.ep1.10.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jboss-aop-0:1.5.5-3.CP05.2.ep1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jboss-cache-0:1.4.1-6.SP14.1.ep1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jboss-remoting-0:2.2.3-3.SP2.ep1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jboss-seam-0:1.2.1-1.ep1.24.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jbossas-0:4.2.0-6.GA_CP09.6.ep1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 4
rh-eap-docs-0:4.2.0-7.GA_CP09.ep1.5.el4
Fixed · RHSA-2010:0376
JBEAP 4.2.0 for RHEL 5
hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jacorb-0:2.3.0-1jpp.ep1.10.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jboss-remoting-0:2.2.3-3.SP2.ep1.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jboss-seam-0:1.2.1-1.ep1.24.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jbossas-0:4.2.0-6.GA_CP09.6.ep1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5
Fixed · RHSA-2010:0378
JBEAP 4.2.0 for RHEL 5
rh-eap-docs-0:4.2.0-7.GA_CP09.ep1.4.1.el5
Fixed · RHSA-2010:0378
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
hsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jacorb-0:2.3.0-1jpp.ep1.10.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-aop-0:1.5.5-3.CP05.2.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-cache-0:1.4.1-6.SP14.1.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-remoting-0:2.2.3-3.SP2.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jboss-seam2-0:2.0.2.FP-1.ep1.23.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jbossas-0:4.3.0-7.GA_CP08.5.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
jbossws-0:2.0.1-5.SP2_CP08.1.ep1.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4
rh-eap-docs-0:4.3.0-7.GA_CP08.ep1.6.el4
Fixed · RHSA-2010:0377
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jacorb-0:2.3.0-1jpp.ep1.10.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-remoting-0:2.2.3-3.SP2.ep1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el5.1
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jboss-seam2-0:2.0.2.FP-1.ep1.23.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jbossas-0:4.3.0-7.GA_CP08.5.ep1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
jbossws-0:2.0.1-5.SP2_CP08.1.ep1.1.el5
Fixed · RHSA-2010:0379
Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5
rh-eap-docs-0:4.3.0-7.GA_CP08.ep1.5.el5
Fixed · RHSA-2010:0379
| Product | Package | State | Advisory |
|---|---|---|---|
| JBEAP 4.2.0 for RHEL 4 | hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | hsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jacorb-0:2.3.0-1jpp.ep1.10.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jboss-aop-0:1.5.5-3.CP05.2.ep1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jboss-cache-0:1.4.1-6.SP14.1.ep1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jboss-remoting-0:2.2.3-3.SP2.ep1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jboss-seam-0:1.2.1-1.ep1.24.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jbossas-0:4.2.0-6.GA_CP09.6.ep1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 4 | rh-eap-docs-0:4.2.0-7.GA_CP09.ep1.5.el4 | Fixed | RHSA-2010:0376 |
| JBEAP 4.2.0 for RHEL 5 | hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jacorb-0:2.3.0-1jpp.ep1.10.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jboss-remoting-0:2.2.3-3.SP2.ep1.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jboss-seam-0:1.2.1-1.ep1.24.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jbossas-0:4.2.0-6.GA_CP09.6.ep1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5 | Fixed | RHSA-2010:0378 |
| JBEAP 4.2.0 for RHEL 5 | rh-eap-docs-0:4.2.0-7.GA_CP09.ep1.4.1.el5 | Fixed | RHSA-2010:0378 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | hsqldb-1:1.8.0.8-3.patch03.1jpp.ep1.3.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jacorb-0:2.3.0-1jpp.ep1.10.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jakarta-commons-httpclient-1:3.0.1-1.patch01.1jpp.ep1.4.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-aop-0:1.5.5-3.CP05.2.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-cache-0:1.4.1-6.SP14.1.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-remoting-0:2.2.3-3.SP2.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jboss-seam2-0:2.0.2.FP-1.ep1.23.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jbossas-0:4.3.0-7.GA_CP08.5.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | jbossws-0:2.0.1-5.SP2_CP08.1.ep1.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 4 | rh-eap-docs-0:4.3.0-7.GA_CP08.ep1.6.el4 | Fixed | RHSA-2010:0377 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | hibernate3-1:3.2.4-1.SP1_CP10.0jpp.ep1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | hibernate3-annotations-0:3.3.1-1.12.GA_CP03.ep1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jacorb-0:2.3.0-1jpp.ep1.10.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-aop-0:1.5.5-3.CP05.2.ep1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-cache-0:1.4.1-6.SP14.1.ep1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-messaging-0:1.4.0-3.SP3_CP10.2.ep1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-remoting-0:2.2.3-3.SP2.ep1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-seam-0:1.2.1-3.JBPAPP_4_3_0_GA.ep1.20.el5.1 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jboss-seam2-0:2.0.2.FP-1.ep1.23.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jbossas-0:4.3.0-7.GA_CP08.5.ep1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jbossts-1:4.2.3-1.SP5_CP09.1jpp.ep1.1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jbossweb-0:2.0.0-6.CP13.0jpp.ep1.1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | jbossws-0:2.0.1-5.SP2_CP08.1.ep1.1.el5 | Fixed | RHSA-2010:0379 |
| Red Hat JBoss Enterprise Application Platform 4.3 for RHEL 5 | rh-eap-docs-0:4.3.0-7.GA_CP08.ep1.5.el5 | Fixed | RHSA-2010:0379 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
1 other source (CISA ADP) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:N/A:N
Date Added
May 25, 2022
Patch Due
Jun 15, 2022
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Aug 14, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 61.49% (0.61487) | 99.14th | v5 (v2026.06.15) |
| Jun 15, 2026 | 62.31% (0.62308) | 99.07th | v5 (v2026.06.15) |
| Apr 3, 2026 | 67.61% (0.67611) | 98.57th | v4 (v2025.03.14) |
| Apr 1, 2026 | 70.33% (0.70331) | 98.67th | v4 (v2025.03.14) |
| May 27, 2025 | 64.97% (0.64971) | 98.34th | v4 (v2025.03.14) |
| May 26, 2025 | 60.68% (0.60680) | 98.16th | v4 (v2025.03.14) |
| Mar 30, 2025 | 63.13% (0.63129) | 98.24th | v4 (v2025.03.14) |
| Mar 29, 2025 | 80.19% (0.80188) | 98.86th | v4 (v2025.03.14) |
| Mar 17, 2025 | 63.13% (0.63129) | 98.23th | v4 (v2025.03.14) |
| Dec 17, 2024 | 76.17% (0.76175) | 98.39th | v3 (v2023.03.01) |
| Jun 29, 2024 | 8.82% (0.08822) | 94.59th | v3 (v2023.03.01) |
| Feb 29, 2024 | 0.88% (0.00881) | 82.04th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.88% (0.00881) | 80.02th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.17% (0.02172) | 80.77th | v2 (v2022.01.01) |
| Feb 13, 2023 | 2.17% (0.02172) | 80.28th | v2 (v2022.01.01) |
| Feb 3, 2023 | 2.69% (0.02686) | 82.44th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.17% (0.02172) | 78.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.17% (0.02172) | 57.73th | v2 (v2022.01.01) |
References (16)
- http://marc.info/?l=bugtraq&m=132698550418872&w=2 vendor-advisoryx_refsource_HPExploitMailing List
- http://secunia.com/advisories/39563 third-party-advisoryx_refsource_SECUNIABroken LinkVendor Advisory
- http://securitytracker.com/id?1023917 vdb-entryx_refsource_SECTRACKBroken LinkThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/39710 vdb-entryx_refsource_BIDBroken LinkThird Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2010/0992 vdb-entryx_refsource_VUPENBroken LinkVendor Advisory
- https://access.redhat.com/security/cve/CVE-2010-1428 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=585899 x_refsource_CONFIRMIssue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58148 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2010-1428
- https://rhn.redhat.com/errata/RHSA-2010-0376.html vendor-advisoryx_refsource_REDHATBroken LinkVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0377.html vendor-advisoryx_refsource_REDHATBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0378.html vendor-advisoryx_refsource_REDHATBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0379.html vendor-advisoryx_refsource_REDHATVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-1428 government-resourceBroken Link
- https://www.cve.org/CVERecord?id=CVE-2010-1428
Change history (7)
- CISA ADP
- SSVC automatable changed from yes to
no yes → no
- CVSS severity changed from HIGH to
MEDIUM HIGH → MEDIUM
- CVSS vector changed from CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N to
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N → CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVSS score changed from 7.5 to
5.9 7.5 → 5.9
- SSVC automatable changed from yes to
no
- CISA ADP
- SSVC automatable changed from no to
yes no → yes
- SSVC automatable changed from no to
yes
- CISA ADP
- SSVC automatable changed from yes to
no yes → no
- SSVC automatable changed from yes to
no
- CISA ADP
- SSVC automatable changed from no to
yes no → yes
- SSVC automatable changed from no to
yes