VDB
CVE-2009-3554
CVE-2009-3554
PUBLISHED
CVSS 7.5 HIGH
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.
EPSS 0.07% · 20.4th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.07%
20.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
Exploit Intelligence
- secretnonempty/CVE-2014-0224 (github-poc)
- secretnonempty/CVE-2014-0224 (github-poc)
- secretnonempty/CVE-2014-0224 (github-poc)
- secretnonempty/CVE-2014-0224 (github-poc)
- ssllabs/openssl-ccs-cve-2014-0224 (github-poc)
- ssllabs/openssl-ccs-cve-2014-0224 (github-poc)
- ssllabs/openssl-ccs-cve-2014-0224 (github-poc)
- ssllabs/openssl-ccs-cve-2014-0224 (github-poc)
- Used for evaluating hosts for CVE-2014-0224 (github-poc)
- Used for evaluating hosts for CVE-2014-0224 (github-poc)
…and 41 more exploits
Timeline
- Dec 15, 2009 CVE Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
References
- https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03824583 advisory
- RHSA-2010:0379 vendor-advisory
- RHSA-2010:0378 vendor-advisory
- jboss-webconsole-information-disclosure(58148) vdb
- HPSBMU02736 vendor-advisory
- RHSA-2010:0376 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=585899 url
- RHSA-2010:0377 vendor-advisory
- ADV-2010-0992 vdb
- 1023917 vdb
- 39710 vdb
- 39563 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-1428 url