[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

251139

 
 

909

 
 

196159

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-2493Date: (C)2010-08-10   (M)2023-12-22


The default configuration of the deployment descriptor (aka web.xml) in picketlink-sts.war in (1) the security_saml quickstart, (2) the webservice_proxy_security quickstart, (3) the web-console application, (4) the http-invoker application, (5) the gpd-deployer application, (6) the jbpm-console application, (7) the contract application, and (8) the uddi-console application in JBoss Enterprise SOA Platform before 5.0.2 contains GET and POST http-method elements, which allows remote attackers to bypass intended access restrictions via a crafted HTTP request.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECUNIA-40681
http://www.redhat.com/docs/en-US/JBoss_SOA_Platform/5.0.2/html/5.0.2_Release_Notes/index.html
https://bugzilla.redhat.com/show_bug.cgi?id=614774
https://jira.jboss.org/browse/SOA-2105

CPE    13
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0:cp03
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0:cp02
cpe:/a:redhat:jboss_enterprise_soa_platform:4.2.0:cp05
cpe:/a:redhat:jboss_enterprise_soa_platform:4.3.0:cp03
...
CWE    1
CWE-16

© SecPod Technologies