CVE-2010-1429
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression.
- Affected products
- Red Hat Jboss Enterprise Application Platform
- Redhat Jboss Enterprise Application Platform
- ≤ 4.2.0, 4.3.0, 4.2, 4.3
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 53.7% (99th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2010-04-28
CVE-2010-1429 at NVD
8 known exploits for CVE-2010-1429
Proof-of-concept code and exploit modules indexed by Sploitus