HackTesting
HomeArticlesTagsContact

CVE-2010-0738

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

References

https://rhn.redhat.com/errata/RHSA-2010-0379.html
https://rhn.redhat.com/errata/RHSA-2010-0378.html
https://bugzilla.redhat.com/show_bug.cgi?id=574105
https://rhn.redhat.com/errata/RHSA-2010-0376.html
http://securityreason.com/securityalert/8408
https://rhn.redhat.com/errata/RHSA-2010-0377.html
http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35
http://www.vupen.com/english/advisories/2010/0992
http://marc.info/?l=bugtraq&m=132129312609324&w=2
https://exchange.xforce.ibmcloud.com/vulnerabilities/58147
http://marc.info/?l=bugtraq&m=132129312609324&w=2
http://www.securityfocus.com/bid/39710
http://secunia.com/advisories/39563
http://securitytracker.com/id?1023918
Published
Apr 28, 2010 22:00:00 UTC
Updated
Oct 22, 2025 00:05:52 UTC
Reserved
Feb 26, 2010 00:00:00 UTC
  • Home
  • Contact Us
  • Recently Updated CVEs
  • Articles
  • Tags
  • RSS Feed
  • Privacy Policy
© 2026 HackTesting. All rights reserved.