Skip to content
COOEY

EXPOSURES › CVE-2010-0738

CVE-2010-0738

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2010-0738 ↗
⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwareexploited-in-wildunpatched

Red Hat JBoss JMX-Console allowed remote attackers to bypass authentication by exploiting incomplete access control on non-GET/POST HTTP methods.

The JMX-Console web application in Red Hat JBoss Enterprise Application Platform only enforced access control for GET and POST methods, allowing attackers to send requests using other methods to bypass authentication. This is a critical, actively exploited vulnerability linked to ransomware attacks, meaning DIB organizations using JBoss must immediately patch or replace the component to prevent unauthorized access and potential data exfiltration or system compromise.

Shame score — A critical, actively exploited vulnerability in a widely deployed enterprise platform that was linked to ransomware attacks, demonstrating severe negligence in patching and access control implementation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Red Hat OpenShift Service on AWS (ROSA)
Red Hat
In Process