CVE-2010-1428
Red Hat JBoss Information Disclosure Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 62.31% probability · 99th percentile
- CISA KEV
- Listed 25 May 2022 · due 15 June 2022 · used in ransomware campaigns
- Weakness
- CWE-749
- Affected
- redhat/jboss enterprise application platform
- Source
- secalert@redhat.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2010-1428
References
- http://marc.info/?l=bugtraq&m=132698550418872&w=2Exploit, Mailing List
- http://secunia.com/advisories/39563Broken Link, Vendor Advisory
- http://securitytracker.com/id?1023917Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/39710Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/0992Broken Link, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=585899Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58148Third Party Advisory, VDB Entry
- https://rhn.redhat.com/errata/RHSA-2010-0376.htmlBroken Link, Vendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0377.htmlBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0378.htmlBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0379.htmlVendor Advisory
- http://marc.info/?l=bugtraq&m=132698550418872&w=2Exploit, Mailing List
- http://secunia.com/advisories/39563Broken Link, Vendor Advisory
- http://securitytracker.com/id?1023917Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/39710Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/0992Broken Link, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=585899Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58148Third Party Advisory, VDB Entry
- https://rhn.redhat.com/errata/RHSA-2010-0376.htmlBroken Link, Vendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0377.htmlBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0378.htmlBroken Link
- https://rhn.redhat.com/errata/RHSA-2010-0379.htmlVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-1428Broken Link
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.