The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
Link | Tags |
---|---|
https://rhn.redhat.com/errata/RHSA-2010-0379.html | vendor advisory |
https://rhn.redhat.com/errata/RHSA-2010-0378.html | vendor advisory broken link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/58148 | vdb entry third party advisory |
http://marc.info/?l=bugtraq&m=132698550418872&w=2 | mailing list exploit vendor advisory |
https://rhn.redhat.com/errata/RHSA-2010-0376.html | vendor advisory broken link |
https://bugzilla.redhat.com/show_bug.cgi?id=585899 | issue tracking |
https://rhn.redhat.com/errata/RHSA-2010-0377.html | vendor advisory broken link |
http://www.vupen.com/english/advisories/2010/0992 | vdb entry broken link vendor advisory |
http://securitytracker.com/id?1023917 | vdb entry third party advisory broken link |
http://www.securityfocus.com/bid/39710 | vdb entry third party advisory broken link |
http://secunia.com/advisories/39563 | broken link third party advisory vendor advisory |