CVE-2010-0738
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
- Affected products
- Red Hat Jboss Enterprise Application Platform
- Redhat Jboss Enterprise Application Platform
- = 4.2.0, 4.3.0
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 79.4% (100th percentile)
- Weakness
- CWE-749
- NVD status
- Analyzed
- Published
- 2010-04-28
CVE-2010-0738 at NVD
31 known exploits for CVE-2010-0738
Proof-of-concept code and exploit modules indexed by Sploitus
jboss-autopwn
jboss-autopwn-1
JBoss Scanner
Exploit for CVE-2005-2006
clusterd - Application Server Attack Toolkit
Hewlett-Packard UCMDB 10.10 JMX-Console Authentication Bypass Vulnerability
Hewlett-Packard (HP) UCMDB - JMX-Console Authentication Bypass
Hewlett-Packard UCMDB 10.10 JMX-Console Authentication Bypass
JBoss JMX Console DeploymentFileRepository WAR Upload and Deployment
JBoss JMX Console Beanshell Deployer WAR Upload and Deployment
JBoss, JMX Console, misconfigured DeploymentScanner
JBoss JMX Console Beanshell Deployer WAR upload and deployment
JBoss JMX Console Deployer Upload and Execute
SAP URL Scanner
JBoss addURL Misconfiguration Attack
JBoss & JMX Console - Misconfigured Deployment Scanner
JBoss addURL Misconfiguration Attack
JBoss, JMX Console, misconfigured DeploymentScanner
JBoss Application Server 4.2 < 4.2.0.CP09 / 4.3 < 4.3.0.CP08 - Remote Command Execution
JBoss JMX - Console Beanshell Deployer WAR Upload and Deployment (Metasploit)
JBoss - Java Class DeploymentFileRepository WAR Deployment (Metasploit)
JBoss JMX Console Beanshell Deployer WAR Upload And Deployment
JBoss Vulnerability Scanner
RedHat JBoss Enterprise Application Platform JMX Console Authentication Bypass
RedHat JBoss Enterprise Application Platform JMX Console Authentication Bypass
RedHat JBoss Enterprise Application Platform JMX Console Authentication Bypass
RedHat JBoss Enterprise Application Platform JMX Console Authentication Bypass
JBoss企业应用平台多个非授权访问漏洞
Immunity Canvas: JBOSS_JMXCONSOLE_DEPLOYER
JBoss Java Class DeploymentFileRepository WAR Deployment
JBoss JMX Console Beanshell Deployer WAR Upload and Deployment