The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2010-04-28T22:00:00

Updated: 2017-08-16T14:57:01

Reserved: 2010-04-15T00:00:00


Link: CVE-2010-1428

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2010-04-28T22:30:00.793

Modified: 2017-08-17T01:32:21.977


Link: CVE-2010-1428

JSON object: View

cve-icon Redhat Information

No data.

CWE