CVE Tools

Description

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

In plain language

AI Act now

CVE-2010-0738 is a JBoss EAP JMX Console access-control flaw that lets remote attackers bypass protections and reach the JMX Console by using the “wrong” request method; if you run an affected JBoss EAP 4.2 or 4.3 (older than the listed fixes) and it’s reachable over the internet, you should worry and act now.

Executive summary

CVE-2010-0738 is an access-control weakness in the JMX-Console web application in JBoss Enterprise Application Platform (JBEAP) where access checks are applied only to GET/POST, allowing remote attackers to invoke the JMX Console GET handler via a different HTTP method; CISA lists it in KEV with real-world use in ransomware campaigns.

If affected, business impact
Unauthorized access to admin functionsPotential service takeoverRansomware riskOperational disruption

What to do now

  1. Check whether you run Red Hat JBoss Enterprise Application Platform (JBoss EAP) 4.2 earlier than 4.2.0.CP09 or 4.3 earlier than 4.3.0.CP08.
  2. Verify whether the JMX-Console web application is enabled and reachable from untrusted networks (especially the public internet).
  3. If either is true, plan an update using Red Hat’s vendor errata for the affected JBoss EAP version and upgrade to 4.2.0.CP09 or later / 4.3.0.CP08 or later.
  4. If you cannot patch immediately, restrict network access so the JMX-Console endpoint is not reachable from the internet (allow only trusted internal management networks/VPN).
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:NI:LA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:NConfidentiality
None
I:LIntegrity
Low
A:NAvailability
None

Weaknesses

Affected Products

and 2 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:May 25, 2022
Remediation due:Jun 15, 2022
Ransomware:Known ransomware use

Required action: Apply updates per vendor instructions.

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

References

and 14 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2010-0738 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows