PoC Index

CVE-2010-0738

KEV RANSOMWAREMEDIUM 5.3EPSS 79.4%

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
79.42% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-05-25, used in ransomware campaigns
Published
2010-04-28
Updated
2026-08-14

Metasploit modules (1)

ExploitDB entries (4)

References

Related