CVE-2010-1428
HIGH(7.5)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVSS 7.5 — Hoch
- EPSS 62%
- Im CISA KEV-Katalog (aktiv ausgenutzt)
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
62.3%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
7.5
Technische Schwere
SecBoard-Einordnung
CVE-2010-1428 betrifft die Web Console von JBoss Enterprise Application Platform (EAP) Versionen 4.2 und 4.3. Die Schwachstelle ermöglicht es entfernten Angreifern, sensible Informationen zu erhalten, da die Zugriffskontrolle nur für GET- und POST-Methoden implementiert ist. Dies erlaubt die Umgehung von Sicherheitsmaßnahmen durch die Verwendung anderer HTTP-Methoden. Die Schwachstelle wird als kritisch eingestuft, mit einem CVSS-Score von 7.5 (HIGH) und einer EPSS-Wahrscheinlichkeit von 62%, dass sie ausgenutzt wird. Besonders besorgniserregend ist, dass diese CVE in CISA's Known Exploited Vulnerabilities (KEV) Katalog gelistet ist, was bedeutet, dass sie aktiv ausgenutzt wird. Security-Teams sollten umgehend die betroffenen JBoss EAP-Installationen auf die gepatchten Versionen (4.2.0.CP09 oder höher für 4.2, 4.3.0.CP08 oder höher für 4.3) aktualisieren. Eine schnelle Priorisierung ist aufgrund der aktiven Ausnutzung und der potenziellen Offenlegung sensibler Daten unerlässlich.
KI-gestützte Einordnung auf Basis der NVD-Daten.
Beschreibung
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.
Betroffene Produkte
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:-:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:-:*:*:*:*:*:*
Referenzen
- http://marc.info/?l=bugtraq&m=132698550418872&w=2
- http://secunia.com/advisories/39563
- http://securitytracker.com/id?1023917
- http://www.securityfocus.com/bid/39710
- http://www.vupen.com/english/advisories/2010/0992
- https://bugzilla.redhat.com/show_bug.cgi?id=585899
- https://exchange.xforce.ibmcloud.com/vulnerabilities/58148
- https://rhn.redhat.com/errata/RHSA-2010-0376.html
- https://rhn.redhat.com/errata/RHSA-2010-0377.html
- https://rhn.redhat.com/errata/RHSA-2010-0378.html