The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Oct 2025 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 07 Feb 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-749 | |
| Metrics |
kev
|
Tue, 13 Aug 2024 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: redhat
Published: 2010-04-28T22:00:00.000Z
Updated: 2025-10-22T00:05:52.450Z
Reserved: 2010-04-15T00:00:00.000Z
Link: CVE-2010-1428
Updated: 2024-08-07T01:21:19.108Z
Status : Deferred
Published: 2010-04-28T22:30:00.793
Modified: 2025-10-22T01:15:36.593
Link: CVE-2010-1428