CISA Known Exploited Vulnerability

CVE-2010-1428 Ransomware

Red Hat · JBoss

Red Hat JBoss Information Disclosure Vulnerability

Date added
BOD 22-01 due date
CWE CWE-264
Ransomware Known

CISA description

Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.

Required action

Apply updates per vendor instructions.