4.3

CVE-2010-3878

Cross-site request forgery (CSRF) vulnerability in the JMX Console in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 before 4.3.0.CP09 allows remote attackers to hijack the authentication of administrators for requests that deploy WAR files.

Data is provided by the National Vulnerability Database (NVD)
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp01
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp02
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp03
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp04
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp05
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp06
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp07
RedhatJboss Enterprise Application Platform Version4.3.0 Updatecp08
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.3
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.