CVE-2010-0738

MEDIUM KEV RANSOMWARE

JBoss JMX Console Deployer Upload and Execute

Title source: metasploit

Description

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

Exploits (12)

nomisec WORKING POC 1 stars
by gitcollect · poc
https://github.com/gitcollect/jboss-autopwn
nomisec WORKING POC
by 1872892142 · poc
https://github.com/1872892142/jboss-autopwn-1
metasploit WORKING POC EXCELLENT
by Patrick Hof, jduck, Konrads Smelkovs, h0ng10 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/jboss_bshdeployer.rb
metasploit WORKING POC EXCELLENT
by jduck, Patrick Hof, h0ng10 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/jboss_maindeployer.rb
metasploit SCANNER
by Chris John Riley · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/sap/sap_icm_urlscan.rb
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16316
exploitdb WORKING POC VERIFIED
by kingcope · perlwebappsjsp
https://www.exploit-db.com/exploits/16274
exploitdb WORKING POC
by y0ug · perlwebappsjsp
https://www.exploit-db.com/exploits/17924
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/jboss_deploymentfilerepository.rb
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16319
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/jboss_bshdeployer.rb
metasploit WORKING POC EXCELLENT
by MC, Jacob Giannantonio, Patrick Hof, h0ng10 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/jboss_deploymentfilerepository.rb

Scores

CVSS v3 5.3
EPSS 0.9085
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Exploitation Intel

CISA KEV 2022-05-25
VulnCheck KEV 2015-08-05
InTheWild.io 2016-04-18
ENISA EUVD EUVD-2010-0764
Ransomware Use Confirmed

Classification

CWE
CWE-749
Status draft

Affected Products (2)

redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform

Timeline

Published Apr 28, 2010
KEV Added May 25, 2022
Tracked Since Feb 18, 2026