5
CVSSv2

CVE-2010-1428

Published: 28/04/2010 Updated: 17/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 447
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 prior to 4.2.0.CP09 and 4.3 prior to 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote malicious users to obtain sensitive information via an unspecified request that uses a different method.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform 4.2.0

redhat jboss enterprise application platform 4.3.0

redhat jboss enterprise application platform

redhat jboss enterprise application platform 4.2

redhat jboss enterprise application platform 4.3

Vendor Advisories

Synopsis Critical: JBoss Enterprise Application Platform 430CP08 update Type/Severity Security Advisory: Critical Topic Updated JBoss Enterprise Application Platform (JBEAP) 43 packages that fixthree security issues and multiple bugs are now available for Red HatEnterprise Linux 5 as JBEAP 430CP08Th ...