Executive brief
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform fails to properly restrict access methods. It performs access control only for GET and POST methods, allowing remote attackers to bypass authentication by using alternative HTTP methods to reach the GET handler.
Affected products
- Red Hat JBoss Enterprise Application Platform (JBoss EAP) 4.2 before 4.2.0.CP09, 4.3 before 4.3.0.CP08
Timeline
- 2010-04-26: disclosed: Date based on CVE ID and early references.
- 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-05-25: advisory: NVD publication date.