Vulnerability record · CVE-2010-1428 · published 28 April 2010
CVE-2010-1428: JBoss EAP Web Console access control bypass via non-GET/POST methods
Redhat · Jboss Enterprise Application Platform
The Web Console in JBoss Enterprise Application Platform enforces access control only for GET and POST requests, so any other HTTP method bypasses the check. An unauthenticated remote attacker can therefore reach console functionality that should be restricted and read sensitive information. The flaw affects JBoss EAP 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08.
Description
The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
critical priorityThe flaw is remotely exploitable without authentication, is listed in CISA KEV with known ransomware use, and has a very high EPSS score.
What it is
The Web Console in JBoss Enterprise Application Platform enforces access control only for GET and POST requests, so any other HTTP method bypasses the check. An unauthenticated remote attacker can therefore reach console functionality that should be restricted and read sensitive information. The flaw affects JBoss EAP 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08.
Impact
An attacker gains unauthorized read access to sensitive information exposed by the Web Console, without needing credentials. There is no integrity or availability impact per the CVSS vector.
Attack surface
Reachable over the network through the JBoss Web Console HTTP interface; the CVSS vector shows no privileges required and no user interaction. The attacker only needs to send a request using an HTTP method other than GET or POST.
Exploitation
CVE-2010-1428 is listed in CISA KEV with a due date of 2022-06-15 and known ransomware campaign use, and EPSS is 0.62308 (99.14th percentile). A reference is tagged Exploit, indicating public exploit material exists.
What to do
- Apply the Red Hat JBoss EAP updates referenced in RHSA-2010-0376 through RHSA-2010-0379 (4.2.0.CP09 / 4.3.0.CP08 or later).
- If patching is not immediately possible, restrict network access to the JBoss Web Console to trusted management hosts only.
- Disable or remove the Web Console where it is not operationally required.
- Place the console behind a reverse proxy or WAF that rejects unexpected HTTP methods and enforces authentication.
- Review JBoss EAP instances for unsupported versions and plan migration off end-of-life releases.
Detection
- Inspect web server and JBoss access logs for requests to Web Console paths using HTTP methods other than GET and POST (for example PUT, DELETE, OPTIONS, TRACE, HEAD).
- Alert on Web Console access from IP addresses outside the expected management network.
- Monitor for anomalous or repeated requests to console endpoints that return sensitive data without prior authentication.
- Correlate console access events with authentication logs to flag unauthenticated access to restricted resources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2010-1428 to the Known Exploited Vulnerabilities catalog on 25 May 2022 as "Red Hat JBoss Information Disclosure Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 15 June 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-1428 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-1428), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.