target entity

JBoss

2 source-linked records in the current knowledge graph.

high

CVE-2010-1428: Red Hat JBoss Information Disclosure Vulnerability

Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information. Required action: Apply updates per vendor instructions.

CVE-2010-1428EPSS 62.3%JBossRed Hat
CISA KEV ↗ · unattributed attribution
high

CVE-2010-0738: Red Hat JBoss Authentication Bypass Vulnerability

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method. Required action: Apply updates per vendor instructions.

CVE-2010-0738EPSS 79.4%JBossRed Hat
CISA KEV ↗ · unattributed attribution