← CVE Tracker
7.5HIGHCISA KEV — actively exploited

CVE-2010-1428 — The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss…

Redhat · Jboss Enterprise Application Platform · Published 28 Apr 2010 · Modified 2 Oct 2026

Description

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.

References

What to do
  1. Check whether Jboss Enterprise Application Platform is in your asset inventory.
  2. Exploitation confirmed — patch within 72 hours.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2010-1428