CVE-2010-0738
MEDIUM KEV RANSOMWAREJBoss JMX Console Deployer Upload and Execute
Title source: metasploitDescription
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
Exploits (12)
metasploit
WORKING POC
EXCELLENT
by Patrick Hof, jduck, Konrads Smelkovs, h0ng10 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/jboss_bshdeployer.rb
metasploit
WORKING POC
EXCELLENT
by jduck, Patrick Hof, h0ng10 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/jboss_maindeployer.rb
metasploit
SCANNER
by Chris John Riley · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/sap/sap_icm_urlscan.rb
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16316
exploitdb
WORKING POC
VERIFIED
by kingcope · perlwebappsjsp
https://www.exploit-db.com/exploits/16274
metasploit
WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/jboss_deploymentfilerepository.rb
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16319
metasploit
WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/jboss_bshdeployer.rb
metasploit
WORKING POC
EXCELLENT
by MC, Jacob Giannantonio, Patrick Hof, h0ng10 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/jboss_deploymentfilerepository.rb
References (14)
Scores
CVSS v3
5.3
EPSS
0.9085
EPSS Percentile
99.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitation Intel
CISA KEV
2022-05-25
VulnCheck KEV
2015-08-05
InTheWild.io
2016-04-18
ENISA EUVD
EUVD-2010-0764
Ransomware Use
Confirmed
Classification
CWE
CWE-749
Status
draft
Affected Products (2)
redhat/jboss_enterprise_application_platform
redhat/jboss_enterprise_application_platform
Timeline
Published
Apr 28, 2010
KEV Added
May 25, 2022
Tracked Since
Feb 18, 2026