VDB

CVE-2010-3862

CVE-2010-3862 PUBLISHED CVSS 2.5999999046325684 LOW

The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09, and 5.1.0; and JBoss Enterprise Web Platform (aka JBEWP) 5.1.0; allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data.

EPSS 2.61% · 84.2th percentile

Risk Scores

CVSS 2.0
2.5999999046325684
EPSS Score
2.61%
84.2th percentile

Affected Products

VendorProductVersions
redhatjboss_remoting2.2.2, 2.2.0, 2.2.2
redhatjboss_enterprise_application_platform4.3.0, 4.3.0, 4.3.0
redhatjboss_enterprise_web_platform5.1.0
n/an/an/a

Timeline

  • Dec 30, 2010 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 3, 2023 EPSS Score
  • Feb 13, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 26, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›