VDB
CVE-2011-4605
CVE-2011-4605
PUBLISHED
CVSS 7.5 HIGH
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.
EPSS 2.02% · 84.1th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
2.02%
84.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
Exploit Intelligence
- secretnonempty/CVE-2014-0224 (github-poc)
- secretnonempty/CVE-2014-0224 (github-poc)
- secretnonempty/CVE-2014-0224 (github-poc)
- secretnonempty/CVE-2014-0224 (github-poc)
- secretnonempty/CVE-2014-0224 (github-poc)
- ssllabs/openssl-ccs-cve-2014-0224 (github-poc)
- ssllabs/openssl-ccs-cve-2014-0224 (github-poc)
- ssllabs/openssl-ccs-cve-2014-0224 (github-poc)
- ssllabs/openssl-ccs-cve-2014-0224 (github-poc)
- ssllabs/openssl-ccs-cve-2014-0224 (github-poc)
…and 49 more exploits
Timeline
- Nov 23, 2012 CVE Published
- Apr 1, 2013 CVE Updated
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c03824583 advisory
- RHSA-2010:0379 vendor-advisory
- RHSA-2010:0378 vendor-advisory
- jboss-webconsole-information-disclosure(58148) vdb
- HPSBMU02736 vendor-advisory
- RHSA-2010:0376 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=585899 url
- RHSA-2010:0377 vendor-advisory
- ADV-2010-0992 vdb
- 1023917 vdb
- 39710 vdb
- 39563 third-party-advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-1428 url