← Back to browse · API

CVE-2010-1428

Severity
HIGH
CVSS
7.5
EPSS
0.62308
Risk score
76.81
CISA KEV
Yes
PoC
No
Published
2022-05-25
Modified
2022-05-25
First seen
2026-08-07
Aliases
EUVD-2010-1456, GHSA-VCWG-4772-7RVX
Products
Red Hat:JBoss, n/a:n/a n/a
Sources
euvd EUVD-2010-1456
cisa.gov CVE-2010-1428

Description

Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.

References