CVE-2010-0738
Description
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
In plain language
AI Act nowCVE-2010-0738 is a JBoss EAP JMX Console access-control flaw that lets remote attackers bypass protections and reach the JMX Console by using the “wrong” request method; if you run an affected JBoss EAP 4.2 or 4.3 (older than the listed fixes) and it’s reachable over the internet, you should worry and act now.
CVE-2010-0738 is an access-control weakness in the JMX-Console web application in JBoss Enterprise Application Platform (JBEAP) where access checks are applied only to GET/POST, allowing remote attackers to invoke the JMX Console GET handler via a different HTTP method; CISA lists it in KEV with real-world use in ransomware campaigns.
What to do now
- Check whether you run Red Hat JBoss Enterprise Application Platform (JBoss EAP) 4.2 earlier than 4.2.0.CP09 or 4.3 earlier than 4.3.0.CP08.
- Verify whether the JMX-Console web application is enabled and reachable from untrusted networks (especially the public internet).
- If either is true, plan an update using Red Hat’s vendor errata for the affected JBoss EAP version and upgrade to 4.2.0.CP09 or later / 4.3.0.CP08 or later.
- If you cannot patch immediately, restrict network access so the JMX-Console endpoint is not reachable from the internet (allow only trusted internal management networks/VPN).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2010-0738 and every CVE in our database. Create a free account — no credit card required.
Create Free Account