CVE-2010-1428 PUBLISHED KEV CVSS 5 MEDIUM

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.

EPSS 65.34% · 98.5th percentile

Risk Scores

CVSS v2.0
5
EPSS Score
65.34%
98.5th percentile

Affected Products

VendorProductVersions
n/an/an/a
redhatjboss_enterprise_application_platform4.2.0, 4.3.0, 4.2.0

Timeline

References

…and 1 more

Open in Interactive Console →