CVE-2010-0738
KEV RANSOMWAREMEDIUM 5.3EPSS 79.4%
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
- CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N - CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 79.42% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-05-25, used in ransomware campaigns
- Published
- 2010-04-28
- Updated
- 2026-08-14
Metasploit modules (1)
ExploitDB entries (4)
- https://www.exploit-db.com/exploits/16319
- https://www.exploit-db.com/exploits/16316
- https://www.exploit-db.com/exploits/16274
- https://www.exploit-db.com/exploits/17924