← Vulnerability feed

Vulnerability record · CVE-2010-0738 · published 28 April 2010

CVE-2010-0738: JBoss JMX-Console access control bypass via non-GET/POST HTTP methods

Redhat · Jboss Enterprise Application Platform

The JMX-Console web application in Red Hat JBoss EAP 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 enforces access control only for GET and POST requests. Requests using any other HTTP method reach the GET handler without the intended authorization check, allowing unauthenticated access to JMX-Console functionality.

5.3 CVSS 3.1 Medium CISA KEV since 25 May 2022 Known ransomware use EPSS 79% · top 0.4% CWE-749 · CWE-749
5.3CVSS 3.1 base score, v2 5.0
79%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
27References, 2 tagged exploit
14 Aug 2026Last modified by NVD

Description

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is an unauthenticated network-reachable access control bypass listed in CISA KEV with documented ransomware use and a very high EPSS score.

What it is

The JMX-Console web application in Red Hat JBoss EAP 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 enforces access control only for GET and POST requests. Requests using any other HTTP method reach the GET handler without the intended authorization check, allowing unauthenticated access to JMX-Console functionality.

Impact

An attacker gains unauthenticated access to the JMX-Console, which can expose management operations and enable further compromise of the JBoss instance. The CVSS vector indicates limited integrity impact only, with no confidentiality or availability impact recorded.

Attack surface

Reachable over the network against the JMX-Console web application; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N). The flaw is triggered by sending a request with an HTTP method other than GET or POST.

Exploitation

CVE-2010-0738 is listed in CISA KEV with known ransomware campaign use, and EPSS shows a 30-day probability of 0.79415 (99.582 percentile). A reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the vendor updates referenced in the Red Hat errata (RHSA-2010-0376 through RHSA-2010-0379) to move to JBoss EAP 4.2.0.CP09 or 4.3.0.CP08 or later.
  • If patching is not immediately possible, restrict network access to the JMX-Console so it is not reachable from untrusted networks.
  • Disable or remove the JMX-Console web application where it is not operationally required.
  • Enforce authentication and authorization at a reverse proxy or web server layer that normalizes and validates HTTP methods before requests reach JBoss.

Detection

  • Inspect web server and JBoss access logs for requests to JMX-Console paths using HTTP methods other than GET or POST (for example PUT, DELETE, HEAD, OPTIONS, TRACE).
  • Alert on any unauthenticated access to JMX-Console endpoints, since legitimate administrative use should be authenticated.
  • Monitor for anomalous or unexpected HTTP method usage across the JBoss application server generally.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2010-0738 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Red Hat JBoss Authentication Bypass Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://marc.info/?l=bugtraq&m=132129312609324&w=2 ExploitMailing List
http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35 Third Party Advisory
http://secunia.com/advisories/39563 Broken LinkVendor Advisory
http://securityreason.com/securityalert/8408 Broken Link
http://securitytracker.com/id?1023918 Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/39710 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2010/0992 Broken LinkVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=574105 Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/58147 Third Party AdvisoryVDB Entry
https://rhn.redhat.com/errata/RHSA-2010-0376.html Broken Link
https://rhn.redhat.com/errata/RHSA-2010-0377.html Broken Link
https://rhn.redhat.com/errata/RHSA-2010-0378.html Broken Link
https://rhn.redhat.com/errata/RHSA-2010-0379.html Vendor Advisory
http://marc.info/?l=bugtraq&m=132129312609324&w=2 ExploitMailing List
http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35 Third Party Advisory
http://secunia.com/advisories/39563 Broken LinkVendor Advisory
http://securityreason.com/securityalert/8408 Broken Link
http://securitytracker.com/id?1023918 Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/39710 Broken LinkThird Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2010/0992 Broken LinkVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=574105 Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/58147 Third Party AdvisoryVDB Entry
https://rhn.redhat.com/errata/RHSA-2010-0376.html Broken Link
https://rhn.redhat.com/errata/RHSA-2010-0377.html Broken Link
https://rhn.redhat.com/errata/RHSA-2010-0378.html Broken Link
https://rhn.redhat.com/errata/RHSA-2010-0379.html Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0738 US Government Resource

Track CVE-2010-0738 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-12149JBoss HTTP Invoker deserialization allows remote code executionThe ReadOnlyAccessFilter doFilter method in the JBoss HTTP Invoker deserializes untrusted data without restricting which classes can be loaded. An un…KEVEPSS 91%analysed8.8CVE-2010-1871JBoss Seam 2 EL injection allows remote code executionJBoss Seam 2, as shipped in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, fails to sanitize input used in JBoss Expression Language …KEVEPSS 83%analysed8.1CVE-2017-12617Apache Tomcat Default Servlet JSP upload leads to remote code executionApache Tomcat with HTTP PUT enabled (for example, the Default servlet readonly parameter set to false) allows an attacker to upload a JSP file throug…KEVEPSS 100%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2010-1428JBoss EAP Web Console access control bypass via non-GET/POST methodsThe Web Console in JBoss Enterprise Application Platform enforces access control only for GET and POST requests, so any other HTTP method bypasses th…KEVEPSS 62%analysed10.0CVE-2018-14721Fasterxml jackson-databind server-side request forgery (ssrf) vulnerabilityFasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure …EPSS 10%9.8CVE-2019-14892Fasterxml jackson-databind information exposure vulnerabilityA flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…EPSS 5.6%9.8CVE-2019-17531Fasterxml jackson-databind deserialization of untrusted data vulnerabilityA Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for …EPSS 5.4%

Source: NIST National Vulnerability Database (record CVE-2010-0738), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.