Skip to main content
All vulnerabilities
CVE-2010-0738 Known ransomware use

Red Hat JBoss Authentication Bypass Vulnerability

Red HatJBoss

Added to KEV catalog
25 May 2022
Federal remediation due date
15 June 2022
Weakness classification (CWE)
CWE-264

CISA Description

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

Required action

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2010-0738

Confirm Your Exposure

Is this vulnerability present in your environment?

CRS delivers independent VAPT assessments that identify exactly which known-exploited vulnerabilities exist in your network, applications, and infrastructure.

Explore VAPT Services