CVE-2010-1428

HIGH KEV RANSOMWARE

Red Hat JBoss EAP/JBEAP <4.2.0.CP09-4.3.0.CP08 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2010-1428 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added May 25, 2022, with confirmed use in ransomware campaigns. EIP tracks 1 public exploit from researchers including Tyler Krpata, Zach Grace <@ztgrace>, including a Metasploit module auxiliary/scanner/http/jboss_vulnscan.

AI-analyzed exploit summary This Metasploit module scans JBoss instances for multiple vulnerabilities, including CVE-2010-1428, by checking for unauthenticated access to specific endpoints and testing for HTTP verb tampering to bypass authentication. It does not exploit the vulnerabilities but detects their presence.

Description

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.

Exploits (1)

metasploit SCANNER
by Tyler Krpata, Zach Grace <@ztgrace> · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/jboss_vulnscan.rb

This Metasploit module scans JBoss instances for multiple vulnerabilities, including CVE-2010-1428, by checking for unauthenticated access to specific endpoints and testing for HTTP verb tampering to bypass authentication. It does not exploit the vulnerabilities but detects their presence.

Classification
Scanner 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: JBoss Application Server
No auth needed
Prerequisites: Network access to the JBoss instance · HTTP/HTTPS access to the target endpoints
devstral-2 · analyzed Jun 05, 2026 Full analysis →

References (12)

Core 12
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2010-0379.html
Broken Link vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2010-0378.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/58148
Exploit, Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=132698550418872&w=2
Broken Link, Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2010-0376.html
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=585899
Broken Link vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2010-0377.html
Broken Link, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2010/0992
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1023917
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/39710
Broken Link, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/39563

Scores

CVSS v3 7.5
EPSS 0.6231
EPSS Percentile 99.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact partial

Details

CISA KEV 2022-05-25
VulnCheck KEV 2016-03-25
InTheWild.io 2018-05-02
ENISA EUVD EUVD-2010-1456
Ransomware Use Confirmed
CWE
CWE-749
Status published
Products (2)
redhat/jboss_enterprise_application_platform 4.2.0
redhat/jboss_enterprise_application_platform 4.3.0
Published Apr 28, 2010
KEV Added May 25, 2022
Tracked Since Feb 18, 2026