CVE-2010-0738

MEDIUM KEV RANSOMWARE

JBoss JMX Console Deployer Upload and Execute

Title source: metasploit

Description

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

Exploits (12)

exploitdb WORKING POC VERIFIED
by kingcope · perlwebappsjsp
https://www.exploit-db.com/exploits/16274
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16319
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16316
exploitdb WORKING POC
by y0ug · perlwebappsjsp
https://www.exploit-db.com/exploits/17924
nomisec WORKING POC 1 stars
by gitcollect · poc
https://github.com/gitcollect/jboss-autopwn
nomisec WORKING POC
by 1872892142 · poc
https://github.com/1872892142/jboss-autopwn-1
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/jboss_deploymentfilerepository.rb
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/jboss_bshdeployer.rb
metasploit SCANNER
by Chris John Riley · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/sap/sap_icm_urlscan.rb
metasploit WORKING POC EXCELLENT
by MC, Jacob Giannantonio, Patrick Hof, h0ng10 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/jboss_deploymentfilerepository.rb
metasploit WORKING POC EXCELLENT
by jduck, Patrick Hof, h0ng10 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/jboss_maindeployer.rb
metasploit WORKING POC EXCELLENT
by Patrick Hof, jduck, Konrads Smelkovs, h0ng10 · rubypocjava
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/jboss_bshdeployer.rb

Scores

CVSS v3 5.3
EPSS 0.9152
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Details

CISA KEV 2022-05-25
VulnCheck KEV 2015-08-05
InTheWild.io 2016-04-18
ENISA EUVD EUVD-2010-0764
Ransomware Use Confirmed
CWE
CWE-749
Status published
Products (2)
redhat/jboss_enterprise_application_platform 4.2.0
redhat/jboss_enterprise_application_platform 4.3.0
Published Apr 28, 2010
KEV Added May 25, 2022
Tracked Since Feb 18, 2026