PT-2010-4057 · Red Hat · Jboss Enterprise Portal Platform
Marc Schoenefeld
·
Published
2010-08-09
·
Updated
2010-08-10
·
CVE-2010-2493
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JBoss Enterprise SOA Platform versions prior to 5.0.2
Description
The default configuration of the deployment descriptor in various applications of JBoss Enterprise SOA Platform contains GET and POST http-method elements. This allows remote attackers to bypass intended access restrictions via a crafted HTTP request.
Recommendations
For versions prior to 5.0.2, update to version 5.0.2 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jboss Enterprise Portal Platform