CVE-2010-0738
MEDIUM KEV RANSOMWAREJBoss JMX Console Deployer Upload and Execute
Title source: metasploitExploitation Summary
CVE-2010-0738 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 25, 2022, with confirmed use in ransomware campaigns.
EIP tracks 13 public exploits from researchers including kingcope, Metasploit, y0ug, including a Metasploit module auxiliary/scanner/http/jboss_vulnscan.
AI-analyzed exploit summary This exploit targets a vulnerability in JBoss AS to deploy a malicious JSP file via the BSHDeployer, which then establishes a reverse shell to the attacker's specified IP and port. It leverages the JMX console's HtmlAdaptor to execute arbitrary BeanShell scripts.
Description
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
Exploits (13)
This exploit targets a vulnerability in JBoss AS to deploy a malicious JSP file via the BSHDeployer, which then establishes a reverse shell to the attacker's specified IP and port. It leverages the JMX console's HtmlAdaptor to execute arbitrary BeanShell scripts.
This Metasploit module exploits CVE-2010-0738 by uploading a malicious WAR file via the JBoss JMX Console's BSHDeployer. It leverages the createScriptDeployment method to deploy a JSP payload, achieving remote code execution on vulnerable JBoss servers.
This Metasploit module exploits CVE-2010-0738 by leveraging the JBoss DeploymentFileRepository to deploy a malicious WAR file containing a JSP payload, achieving remote code execution. It supports automatic platform detection and cleanup of deployed files.
This Perl script exploits a misconfigured JBoss JMX Console (CVE-2010-0738) by deploying a malicious WAR file via the DeploymentScanner's addURL method, enabling remote command execution. It includes functionality for installing, executing, and cleaning up the payload, as well as establishing a reverse shell.
This repository contains functional exploit scripts (e.sh and e2.sh) that automate the deployment of a JSP shell on vulnerable JBoss AS servers, leveraging CVE-2010-0738 (authentication bypass via HTTP VERB manipulation). The scripts support multi-platform targets (Linux, Windows, MacOS) and provide interactive shells via bind/reverse connections or Metasploit payloads.
This repository contains functional exploit scripts (e.sh and e2.sh) that leverage CVE-2010-0738, a JBoss authentication bypass vulnerability, to deploy a JSP shell and execute commands on target systems. The scripts support multiple platforms (Linux, Windows, MacOS) and payload types (bind/reverse shells, Meterpreter, VNC).
This Metasploit module scans JBoss instances for multiple vulnerabilities, including CVE-2010-0738, by checking for unauthenticated access to sensitive endpoints and testing for HTTP verb tampering to bypass authentication. It does not exploit the vulnerabilities but detects their presence.
This Metasploit module exploits a vulnerability in JBoss Application Server's DeploymentFileRepository to upload and deploy a malicious WAR file via a JSP stager. It supports both direct POST and chunked HEAD/GET methods for payload delivery.
This Metasploit module exploits CVE-2010-0738 in JBoss servers with exposed 'jmx-console' applications by uploading and deploying a malicious WAR file via the BSHDeployer's createScriptDeployment() method. It supports both direct deployment and a stager-based approach for payload delivery.
This Metasploit module scans SAP Internet Communication Manager (ICM) URLs for authentication bypass vulnerabilities and enumerates accessible paths. It checks for HTTP verb tampering (CVE-2010-0738) and logs valid URLs.
This Metasploit module exploits a vulnerability in JBoss Application Server (CVE-2010-0738) by deploying a malicious WAR file via the DeploymentFileRepository class. It achieves remote code execution by uploading a JSP stager and payload, then executing them on the target system.
This Metasploit module exploits CVE-2010-0738 in JBoss servers with exposed JMX consoles by uploading and deploying a malicious WAR archive via the MainDeployer functionality. It uses a temporary HTTP server to serve the payload and achieves remote code execution.
This Metasploit module exploits CVE-2010-0738 in JBoss servers with exposed 'jmx-console' applications by uploading and deploying a malicious WAR file via the BSHDeployer's createScriptDeployment() method, leading to remote code execution.
References (14)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N