Record summary

CVE-2010-1428 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit. CISA lists CVE-2010-1428 in KEV and reports its use in known ransomware campaigns.

Description

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · May 25, 2022 · CISA
VulnCheck KEV
Listed · Mar 25, 2016 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · CISA

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationActive
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 7, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CISAVersion data not supplied

Proofs of concept

1

Catalogued exploits

MetasploitJBoss Vulnerability ScannerMetasploit auxiliary PoCby Tyler Krpata +1 moreNot analyzed1 file

Ruby · linked to 5 vulnerabilities

Metasploit

PoC details

References

Showing 12 of 13