CVE-2010-0738
Red Hat JBoss Authentication Bypass Vulnerability
5.3
CVSS 3.1
79.4 %
EPSS (current)
2022-05-25
KEV addition
Yes
Ransomware
Timeline
Publication, first public exploit and KEV addition on a day axis.
Key facts
Vendor / product: Red Hat / JBoss
Published: 2010-04-28 · Due (CISA): 2022-06-15
CWE: CWE-749 · EU list: no
Exploit references (metadata only)
| Source | Reference | Title | Date |
|---|---|---|---|
| metasploit | auxiliary/admin/http/jboss_bshdeployer | auxiliary/admin/http/jboss_bshdeployer | – |
| metasploit | auxiliary/admin/http/jboss_deploymentfilerepository | auxiliary/admin/http/jboss_deploymentfilerepository | – |
| metasploit | auxiliary/scanner/http/jboss_vulnscan | auxiliary/scanner/http/jboss_vulnscan | – |
| metasploit | auxiliary/scanner/sap/sap_icm_urlscan | auxiliary/scanner/sap/sap_icm_urlscan | – |
| metasploit | exploit/multi/http/jboss_maindeployer | exploit/multi/http/jboss_maindeployer | 2007-02-20 |
| metasploit | exploit/multi/http/jboss_bshdeployer | exploit/multi/http/jboss_bshdeployer | 2010-04-26 |
| metasploit | exploit/multi/http/jboss_deploymentfilerepository | exploit/multi/http/jboss_deploymentfilerepository | 2010-04-26 |
| exploitdb | 16316 | JBoss - Java Class DeploymentFileRepository WAR Deployment (Metasploit) | 2010-08-03 |
| exploitdb | 16319 | JBoss JMX - Console Beanshell Deployer WAR Upload and Deployment (Metasploit) | 2011-01-10 |
| exploitdb | 16274 | JBoss Application Server 4.2 < 4.2.0.CP09 / 4.3 < 4.3.0.CP08 - Remote Command Execution | 2011-03-04 |
| exploitdb | 17924 | JBoss & JMX Console - Misconfigured Deployment Scanner | 2011-10-03 |
References only — no downloads or instructions.