VulnerabilityModified
CVE-2010-2474
JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.
LOW 3.5EPSS 0.90%
Does this matter?
Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.
Description
JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.
- CVSS 2.0
- 3.5 LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
- EPSS
- 0.90% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- redhat/jboss enterprise service bus · redhat/jboss enterprise soa platform
- Source
- secalert@redhat.com
References
- http://secunia.com/advisories/40568Vendor Advisory
- http://secunia.com/advisories/40681Vendor Advisory
- http://www.redhat.com/docs/en-US/JBoss_SOA_Platform/5.0.2/html/5.0.2_Release_Notes/index.html
- https://bugzilla.redhat.com/show_bug.cgi?id=609442
- https://jira.jboss.org/browse/JBESB-3345
- http://secunia.com/advisories/40568Vendor Advisory
- http://secunia.com/advisories/40681Vendor Advisory
- http://www.redhat.com/docs/en-US/JBoss_SOA_Platform/5.0.2/html/5.0.2_Release_Notes/index.html
- https://bugzilla.redhat.com/show_bug.cgi?id=609442
- https://jira.jboss.org/browse/JBESB-3345
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.