CVE-2010-1429

Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:jboss_enterprise_application_platform:*:cp08:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:*:cp07:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp01:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp02:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp03:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp04:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp05:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp06:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp07:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp01:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp02:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp03:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp04:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp05:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp06:*:*:*:*:*:*

History

21 Nov 2024, 01:14

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=132698550418872&w=2 - () http://marc.info/?l=bugtraq&m=132698550418872&w=2 -
References () http://secunia.com/advisories/39563 - Vendor Advisory () http://secunia.com/advisories/39563 - Vendor Advisory
References () http://securitytracker.com/id?1023918 - () http://securitytracker.com/id?1023918 -
References () http://www.securityfocus.com/bid/39710 - () http://www.securityfocus.com/bid/39710 -
References () http://www.vupen.com/english/advisories/2010/0992 - Vendor Advisory () http://www.vupen.com/english/advisories/2010/0992 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=585900 - () https://bugzilla.redhat.com/show_bug.cgi?id=585900 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/58149 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/58149 -
References () https://rhn.redhat.com/errata/RHSA-2010-0376.html - Vendor Advisory () https://rhn.redhat.com/errata/RHSA-2010-0376.html - Vendor Advisory
References () https://rhn.redhat.com/errata/RHSA-2010-0377.html - Vendor Advisory () https://rhn.redhat.com/errata/RHSA-2010-0377.html - Vendor Advisory
References () https://rhn.redhat.com/errata/RHSA-2010-0378.html - Vendor Advisory () https://rhn.redhat.com/errata/RHSA-2010-0378.html - Vendor Advisory
References () https://rhn.redhat.com/errata/RHSA-2010-0379.html - Vendor Advisory () https://rhn.redhat.com/errata/RHSA-2010-0379.html - Vendor Advisory
References () https://www.exploit-db.com/exploits/44009/ - () https://www.exploit-db.com/exploits/44009/ -

07 Nov 2023, 02:05

Type Values Removed Values Added
Summary Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression. Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression.

Information

Published : 2010-04-28 22:30

Updated : 2024-11-21 01:14


NVD link : CVE-2010-1429

Mitre link : CVE-2010-1429

CVE.ORG link : CVE-2010-1429


JSON object : View

Products Affected

redhat

  • jboss_enterprise_application_platform
CWE
CWE-264

Permissions, Privileges, and Access Controls