CVE-2010-0738
Red Hat JBoss Authentication Bypass Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 79.42% probability · 100th percentile
- CISA KEV
- Listed 25 May 2022 · due 15 June 2022 · used in ransomware campaigns
- Weakness
- CWE-749
- Affected
- redhat/jboss enterprise application platform
- Source
- secalert@redhat.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2010-0738
References
- http://marc.info/?l=bugtraq&m=132129312609324&w=2Exploit, Mailing List
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35Third Party Advisory
- http://secunia.com/advisories/39563Broken Link, Vendor Advisory
- http://securityreason.com/securityalert/8408Broken Link
- http://securitytracker.com/id?1023918Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/39710Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/0992Broken Link, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=574105Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58147Third Party Advisory, VDB Entry
- https://rhn.redhat.com/errata/RHSA-2010-0376.htmlBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0377.htmlBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0378.htmlBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0379.htmlVendor Advisory
- http://marc.info/?l=bugtraq&m=132129312609324&w=2Exploit, Mailing List
- http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35Third Party Advisory
- http://secunia.com/advisories/39563Broken Link, Vendor Advisory
- http://securityreason.com/securityalert/8408Broken Link
- http://securitytracker.com/id?1023918Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/39710Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/0992Broken Link, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=574105Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58147Third Party Advisory, VDB Entry
- https://rhn.redhat.com/errata/RHSA-2010-0376.htmlBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0377.htmlBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0378.htmlBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0379.htmlVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0738US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.