Skip to content
COOEY

EXPOSURES › CVE-2010-1428

CVE-2010-1428

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-05-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2010-1428 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 ransomwareexploited-in-wildunpatcheddata-breach

An incomplete block on the JBoss Web Console allowed unauthenticated attackers to access sensitive information via HTTP verbs beyond GET and POST.

The JBoss Web Console's default protection was bypassed because it only blocked GET and POST requests, leaving other HTTP verbs exploitable for information disclosure. DIB organizations must ensure that default security controls are fully implemented and that incomplete blocks do not leave critical interfaces exposed to unauthenticated attackers. This failure highlights the risk of relying on partial mitigations and the need for comprehensive access control validation.

Shame score — A default security control was implemented incompletely, allowing unauthenticated access to sensitive data through a known vulnerability that was actively exploited in the wild.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Red Hat OpenShift Service on AWS (ROSA)
Red Hat
In Process