CVE-2010-0738
Executive Summary
The JMX‑Console web application in JBoss EAP 4.2 (pre‑4.2.0.CP09) and 4.3 (pre‑4.3.0.CP08) enforces access control only for GET and POST requests. Attackers can use other HTTP methods to reach the GET handler, bypassing authentication and potentially exposing sensitive data or enabling further exploitation. This flaw is actively exploited in the wild (CISA KEV).
Authoritative CVE Metadata - CVSS Base Score: 5.3 (MEDIUM) - Published: 2010-04-28T22:30:00.447 - Last Modified: 2026-10-02T14:55:30.687
[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2022-05-25)
Original Description: The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.
"Every human being is the author of his own health or disease."
— Buddha