SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2010-2474

JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.

LOW 3.5EPSS 0.90%

Does this matter?

Lower severity and a low EPSS score (0.90%). Track it; it rarely justifies an emergency change on its own.

Description

JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.

CVSS 2.0
3.5 LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
EPSS
0.90% probability · 58th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
redhat/jboss enterprise service bus · redhat/jboss enterprise soa platform
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.