Sploitus

CVE-2010-0738

31 known exploits for CVE-2010-0738

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

Redhat Jboss Enterprise Application Platform
= 4.2.0, 4.3.0
Fix
Available
CVSS 3.1
5.3 MEDIUM
EPSS
79.4% (100th percentile)
Weakness
CWE-749
NVD status
Analyzed
Published
2010-04-28
CVE-2010-0738 at NVD
Authoritative description, scoring and affected products

31 known exploits for CVE-2010-0738

Proof-of-concept code and exploit modules indexed by Sploitus

jboss-autopwn
2026-08-26 KitPloitKITPLOIT
jboss-autopwn-1
2026-08-24 KitPloitKITPLOIT
JBoss Scanner
2024-09-01 Zach Grace, Tyler Krpata, metasploit.comPACKETSTORMRuby
Exploit for CVE-2005-2006
2018-08-06 WGP5GITEE
clusterd - Application Server Attack Toolkit
2017-09-25 KitPloitKITPLOIT
Hewlett-Packard UCMDB 10.10 JMX-Console Authentication Bypass Vulnerability
2015-02-04 Hans-Martin MuenchZDT
Hewlett-Packard (HP) UCMDB - JMX-Console Authentication Bypass
2015-02-03 Hans-Martin MuenchEXPLOITPACK
Hewlett-Packard UCMDB 10.10 JMX-Console Authentication Bypass
2015-02-03 Hans-Martin MuenchPACKETSTORM
JBoss JMX Console DeploymentFileRepository WAR Upload and Deployment
2014-12-08 us3r777 <us3r777@n0b0.so>METASPLOITRuby
JBoss JMX Console Beanshell Deployer WAR Upload and Deployment
2014-07-18 us3r777 <us3r777@n0b0.so>METASPLOITRuby
JBoss, JMX Console, misconfigured DeploymentScanner
2014-07-01 RootSEEBUGPerl
JBoss JMX Console Beanshell Deployer WAR upload and deployment
2014-07-01 RootSEEBUGRuby
JBoss JMX Console Deployer Upload and Execute
2012-07-10 jduck <jduck@metasploit.com>, Patrick Hof, h0ng10METASPLOITRuby
SAP URL Scanner
2011-10-22 Chris John RileyMETASPLOITRuby
JBoss addURL Misconfiguration Attack
2011-10-05 RootSEEBUGPerl
JBoss & JMX Console - Misconfigured Deployment Scanner
2011-10-03 y0ugEXPLOITDBPerl
JBoss addURL Misconfiguration Attack
2011-10-03 y0ugPACKETSTORMPerl
JBoss, JMX Console, misconfigured DeploymentScanner
2011-10-02 y0ugZDTPerl
JBoss Application Server 4.2 < 4.2.0.CP09 / 4.3 < 4.3.0.CP08 - Remote Command Execution
2011-03-04 kingcopeEXPLOITDBPerl
JBoss JMX - Console Beanshell Deployer WAR Upload and Deployment (Metasploit)
2011-01-10 MetasploitEXPLOITDBRuby
JBoss - Java Class DeploymentFileRepository WAR Deployment (Metasploit)
2010-08-03 MetasploitEXPLOITDBRuby
JBoss JMX Console Beanshell Deployer WAR Upload And Deployment
2010-06-24 Patrick HofPACKETSTORMRuby
JBoss Vulnerability Scanner
2010-06-21 Tyler Krpata, Zach Grace <@ztgrace>METASPLOITRuby
RedHat JBoss Enterprise Application Platform JMX Console Authentication Bypass
2010-06-07 SAINT CorporationSAINT
RedHat JBoss Enterprise Application Platform JMX Console Authentication Bypass
2010-06-07 SAINT CorporationSAINT
RedHat JBoss Enterprise Application Platform JMX Console Authentication Bypass
2010-06-07 SAINT CorporationSAINT
RedHat JBoss Enterprise Application Platform JMX Console Authentication Bypass
2010-06-07 SAINT CorporationSAINT
JBoss企业应用平台多个非授权访问漏洞
2010-04-29 RootSEEBUG
Immunity Canvas: JBOSS_JMXCONSOLE_DEPLOYER
2010-04-28 Immunity CanvasCANVAS
JBoss Java Class DeploymentFileRepository WAR Deployment
2010-04-26 MC <mc@metasploit.com>, Jacob Giannantonio, Patrick Hof, h0ng10METASPLOITRuby
JBoss JMX Console Beanshell Deployer WAR Upload and Deployment
2010-04-26 Patrick Hof, jduck <jduck@metasploit.com>, Konrads Smelkovs, h0ng10METASPLOITRuby