CVE-2010-0738

medium

Description

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

References

https://rhn.redhat.com/errata/RHSA-2010-0379.html

https://exchange.xforce.ibmcloud.com/vulnerabilities/58147

https://bugzilla.redhat.com/show_bug.cgi?id=574105

http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35

Details

Source: Mitre, NVD

Published: 2010-04-28

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Severity: Medium