CVE-2010-1429
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 53.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 53.73% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- redhat/jboss enterprise application platform
- Source
- secalert@redhat.com
References
- http://marc.info/?l=bugtraq&m=132698550418872&w=2
- http://secunia.com/advisories/39563Vendor Advisory
- http://securitytracker.com/id?1023918
- http://www.securityfocus.com/bid/39710
- http://www.vupen.com/english/advisories/2010/0992Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=585900
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58149
- https://rhn.redhat.com/errata/RHSA-2010-0376.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0377.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0378.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0379.htmlVendor Advisory
- https://www.exploit-db.com/exploits/44009/
- http://marc.info/?l=bugtraq&m=132698550418872&w=2
- http://secunia.com/advisories/39563Vendor Advisory
- http://securitytracker.com/id?1023918
- http://www.securityfocus.com/bid/39710
- http://www.vupen.com/english/advisories/2010/0992Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=585900
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58149
- https://rhn.redhat.com/errata/RHSA-2010-0376.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0377.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0378.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0379.htmlVendor Advisory
- https://www.exploit-db.com/exploits/44009/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.