---
id: CVE-2010-0738
title: >-
  The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise
  Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3
  before 4.3.0.CP08 performs access control only for the GET and POST methods,
  which allows …
summary: >-
  The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise
  Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3
  before 4.3.0.CP08 performs access control only for the GET and POST methods,
  which allows …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-749
vendor: redhat
product: jboss_enterprise_application_platform
affected:
  - jboss_enterprise_application_platform = 4.2.0
  - jboss_enterprise_application_platform = 4.3.0
published: '2010-04-28'
updated: '2026-08-14'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2010-0738'
references:
  - url: 'http://marc.info/?l=bugtraq&m=132129312609324&w=2'
    label: secalert@redhat.com
  - url: >-
      http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/39563'
    label: secalert@redhat.com
  - url: 'http://securityreason.com/securityalert/8408'
    label: secalert@redhat.com
  - url: 'http://securitytracker.com/id?1023918'
    label: secalert@redhat.com
  - url: 'http://www.securityfocus.com/bid/39710'
    label: secalert@redhat.com
  - url: 'http://www.vupen.com/english/advisories/2010/0992'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=574105'
    label: secalert@redhat.com
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/58147'
    label: secalert@redhat.com
  - url: 'https://rhn.redhat.com/errata/RHSA-2010-0376.html'
    label: secalert@redhat.com
  - url: 'https://rhn.redhat.com/errata/RHSA-2010-0377.html'
    label: secalert@redhat.com
  - url: 'https://rhn.redhat.com/errata/RHSA-2010-0378.html'
    label: secalert@redhat.com
  - url: 'https://rhn.redhat.com/errata/RHSA-2010-0379.html'
    label: secalert@redhat.com
  - url: 'http://marc.info/?l=bugtraq&m=132129312609324&w=2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=35
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/39563'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://securityreason.com/securityalert/8408'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://securitytracker.com/id?1023918'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/39710'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.vupen.com/english/advisories/2010/0992'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=574105'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/58147'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://rhn.redhat.com/errata/RHSA-2010-0376.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://rhn.redhat.com/errata/RHSA-2010-0377.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://rhn.redhat.com/errata/RHSA-2010-0378.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://rhn.redhat.com/errata/RHSA-2010-0379.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-0738
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.79415
epssPercentile: 0.99583
kev: true
kevDateAdded: '2022-05-25'
kevDueDate: '2022-06-15'
kevRansomware: true
exploited: true
exploitAvailable: true
ingestedAt: '2026-08-14T06:15:27.002Z'
exploits:
  exploitdb: true
  github: 2
  githubRepos:
    - 'https://github.com/1872892142/jboss-autopwn-1'
    - 'https://github.com/gitcollect/jboss-autopwn'
  metasploit:
    - auxiliary/admin/http/jboss_bshdeployer
    - auxiliary/admin/http/jboss_deploymentfilerepository
    - auxiliary/scanner/http/jboss_vulnscan
    - auxiliary/scanner/sap/sap_icm_urlscan
    - exploit/multi/http/jboss_bshdeployer
    - exploit/multi/http/jboss_deploymentfilerepository
    - exploit/multi/http/jboss_maindeployer
  checkedAt: '2026-09-23T07:13:14.837Z'
---

## Overview

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

## Affected

- `jboss_enterprise_application_platform = 4.2.0`
- `jboss_enterprise_application_platform = 4.3.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
