SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2010-1428

Red Hat JBoss Information Disclosure Vulnerability

KEVHIGH 7.5EPSS 62.3%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
62.31% probability · 99th percentile
CISA KEV
Listed 25 May 2022 · due 15 June 2022 · used in ransomware campaigns
Weakness
CWE-749
Affected
redhat/jboss enterprise application platform
Source
secalert@redhat.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2010-1428

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.