← Vulnerability feed

Vulnerability record · CVE-2010-1429 · published 28 April 2010

CVE-2010-1429: JBoss EAP status servlet exposes deployed web context information

Redhat · Jboss Enterprise Application Platform

JBoss Enterprise Application Platform 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about deployed web contexts through a request to the status servlet, for example with a full=true query string. The issue is a regression of CVE-2008-3273, meaning an access control fix was lost in these versions.

5.0 CVSS 2.0 Medium EPSS 54% · top 1.0% CWE-264 · Permissions and access controls
5.0CVSS 2.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityUnauthenticated remote information disclosure with public exploit code and a very high EPSS score, though impact is limited to reconnaissance.

What it is

JBoss Enterprise Application Platform 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about deployed web contexts through a request to the status servlet, for example with a full=true query string. The issue is a regression of CVE-2008-3273, meaning an access control fix was lost in these versions.

Impact

An unauthenticated remote attacker learns which web applications are deployed and related context details, useful for reconnaissance and targeting follow-on attacks. No integrity or availability impact is described.

Attack surface

Reachable over the network via HTTP requests to the JBoss status servlet; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS is high (0.53728, 98.9th percentile) and a public Exploit-DB entry exists, indicating exploit code is available.

What to do

  • Apply the Red Hat errata fixes (RHSA-2010-0376 through RHSA-2010-0379) to move to JBoss EAP 4.2.0.CP09 or 4.3.0.CP08 and later.
  • If patching is delayed, restrict network access to the JBoss status servlet to trusted management hosts.
  • Disable or remove the status servlet where it is not operationally required.
  • Verify the CVE-2008-3273 access control fix is present after any upgrade, since this is a regression.

Detection

  • Search web and proxy logs for requests to the JBoss status servlet, especially with a full=true query string.
  • Alert on status servlet requests originating from outside expected management networks.
  • Review JBoss deployments for the status servlet being enabled and externally reachable.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2010-1429 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-12149JBoss HTTP Invoker deserialization allows remote code executionThe ReadOnlyAccessFilter doFilter method in the JBoss HTTP Invoker deserializes untrusted data without restricting which classes can be loaded. An un…KEVEPSS 91%analysed8.8CVE-2010-1871JBoss Seam 2 EL injection allows remote code executionJBoss Seam 2, as shipped in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, fails to sanitize input used in JBoss Expression Language …KEVEPSS 83%analysed8.1CVE-2017-12617Apache Tomcat Default Servlet JSP upload leads to remote code executionApache Tomcat with HTTP PUT enabled (for example, the Default servlet readonly parameter set to false) allows an attacker to upload a JSP file throug…KEVEPSS 100%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2010-1428JBoss EAP Web Console access control bypass via non-GET/POST methodsThe Web Console in JBoss Enterprise Application Platform enforces access control only for GET and POST requests, so any other HTTP method bypasses th…KEVEPSS 62%analysed5.3CVE-2010-0738JBoss JMX-Console access control bypass via non-GET/POST HTTP methodsThe JMX-Console web application in Red Hat JBoss EAP 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 enforces access control only for GET and POST re…KEVEPSS 79%analysed10.0CVE-2018-14721Fasterxml jackson-databind server-side request forgery (ssrf) vulnerabilityFasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure …EPSS 10%9.8CVE-2019-14892Fasterxml jackson-databind information exposure vulnerabilityA flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5 and 2.6.7.3, where it would permit polymorphic deserialization of a mal…EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2010-1429), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.