PT-2010-4057 · Red Hat · Jboss Enterprise Portal Platform

Marc Schoenefeld

·

Published

2010-08-09

·

Updated

2010-08-10

·

CVE-2010-2493

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions JBoss Enterprise SOA Platform versions prior to 5.0.2
Description The default configuration of the deployment descriptor in various applications of JBoss Enterprise SOA Platform contains GET and POST http-method elements. This allows remote attackers to bypass intended access restrictions via a crafted HTTP request.
Recommendations For versions prior to 5.0.2, update to version 5.0.2 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2493

Affected Products

Jboss Enterprise Portal Platform