logo

CVE-2010-0738 - Red Hat JBoss Authentication Bypass Vulnerability

Project:Red Hat

Product:JBoss

Date Added:2022-05-25Due Date:2022-06-15

Vulnerability Name

Red Hat JBoss Authentication Bypass Vulnerability

Description

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

Known To Be Used in Ransomware Campaigns?

Known

Action

Apply updates per vendor instructions.

Additional Notes

https://nvd.nist.gov/vuln/detail/CVE-2010-0738