CVE-2010-0738

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp01:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp02:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp03:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp04:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp05:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp06:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp07:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp08:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp01:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp02:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp03:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp04:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp05:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp06:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp07:*:*:*:*:*:*

History

13 Feb 2023, 04:16

Type Values Removed Values Added
References
  • {'url': 'https://access.redhat.com/security/cve/CVE-2010-0738', 'name': 'https://access.redhat.com/security/cve/CVE-2010-0738', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2010:0376', 'name': 'https://access.redhat.com/errata/RHSA-2010:0376', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/kb/docs/DOC-30741', 'name': 'https://access.redhat.com/kb/docs/DOC-30741', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2010:0379', 'name': 'https://access.redhat.com/errata/RHSA-2010:0379', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2010:0378', 'name': 'https://access.redhat.com/errata/RHSA-2010:0378', 'tags': [], 'refsource': 'MISC'}
  • {'url': 'https://access.redhat.com/errata/RHSA-2010:0377', 'name': 'https://access.redhat.com/errata/RHSA-2010:0377', 'tags': [], 'refsource': 'MISC'}
Summary CVE-2010-0738 JBoss EAP jmx authentication bypass with crafted HTTP request The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

02 Feb 2023, 17:17

Type Values Removed Values Added
Summary The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. CVE-2010-0738 JBoss EAP jmx authentication bypass with crafted HTTP request
References
  • (MISC) https://access.redhat.com/security/cve/CVE-2010-0738 -
  • (MISC) https://access.redhat.com/errata/RHSA-2010:0376 -
  • (MISC) https://access.redhat.com/kb/docs/DOC-30741 -
  • (MISC) https://access.redhat.com/errata/RHSA-2010:0379 -
  • (MISC) https://access.redhat.com/errata/RHSA-2010:0378 -
  • (MISC) https://access.redhat.com/errata/RHSA-2010:0377 -

Information

Published : 2010-04-28 22:30

Updated : 2023-12-10 11:03


NVD link : CVE-2010-0738

Mitre link : CVE-2010-0738

CVE.ORG link : CVE-2010-0738


JSON object : View

Products Affected

redhat

  • jboss_enterprise_application_platform
CWE
CWE-264

Permissions, Privileges, and Access Controls