Executive brief
The Web Console in Red Hat JBoss Application Server fails to properly restrict access for HTTP methods other than GET and POST. An unauthenticated remote attacker can bypass intended access controls to obtain sensitive information by using alternative HTTP verbs.
Affected products
- Red Hat JBoss Enterprise Application Platform (EAP) 4.2 before 4.2.0.CP09, 4.3 before 4.3.0.CP08
Timeline
- 2010-04-26: disclosed: Initial vulnerability disclosure date based on external references (approximate)
- 2022-05-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog