CVE-2010-1428

Executive Summary

The Web Console in JBoss EAP 4.2 (pre‑CP09) and 4.3 (pre‑CP08) enforces access control only for GET and POST requests. Attackers can use other HTTP methods to bypass authentication and retrieve sensitive data, such as configuration or management information, via unspecified requests. This flaw is actively exploited in the wild (CISA KEV).


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2010-04-28T22:30:00.793 - Last Modified: 2026-10-02T14:55:25.677

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2022-05-25)

Original Description: The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.

"Skill to do comes of doing."

— Ralph Emerson
Source: NVD