SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2010-0738

Red Hat JBoss Authentication Bypass Vulnerability

KEVMEDIUM 5.3EPSS 79.4%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
79.42% probability · 100th percentile
CISA KEV
Listed 25 May 2022 · due 15 June 2022 · used in ransomware campaigns
Weakness
CWE-749
Affected
redhat/jboss enterprise application platform
Source
secalert@redhat.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2010-0738

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.