5
CVSSv2

CVE-2010-2493

Published: 10/08/2010 Updated: 10/08/2010
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The default configuration of the deployment descriptor (aka web.xml) in picketlink-sts.war in (1) the security_saml quickstart, (2) the webservice_proxy_security quickstart, (3) the web-console application, (4) the http-invoker application, (5) the gpd-deployer application, (6) the jbpm-console application, (7) the contract application, and (8) the uddi-console application in JBoss Enterprise SOA Platform prior to 5.0.2 contains GET and POST http-method elements, which allows remote malicious users to bypass intended access restrictions via a crafted HTTP request.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise soa platform 4.3.0

redhat jboss enterprise soa platform 5.0.0

redhat jboss enterprise soa platform 4.2.0

redhat jboss enterprise soa platform