5

CVE-2010-1429

Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.  NOTE: this issue exists because of a CVE-2008-3273 regression.

Data is provided by the National Vulnerability Database (NVD)
RedhatJboss Enterprise Application Platform Updatecp08 Version <= 4.2.0
RedhatJboss Enterprise Application Platform Updatecp07 Version <= 4.3.0
RedhatJboss Enterprise Application Platform Version4.2.0 Updatecp01
RedhatJboss Enterprise Application Platform Version4.2.0 Updatecp02
RedhatJboss Enterprise Application Platform Version4.2.0 Updatecp03
RedhatJboss Enterprise Application Platform Version4.2.0 Updatecp04
RedhatJboss Enterprise Application Platform Version4.2.0 Updatecp05
RedhatJboss Enterprise Application Platform Version4.2.0 Updatecp06
RedhatJboss Enterprise Application Platform Version4.2.0 Updatecp07
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp01
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp02
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp03
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp04
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp05
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp06
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 21.19% 0.955
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N