Vulnerability Name:

CVE-2010-1429 (CCN-58149)

Assigned:2010-04-26
Published:2010-04-26
Updated:2023-02-13
Summary:
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
4.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
4.1 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:F/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2010-1429

Source: CCN
Type: HP Security Bulletin HPSBMU02736 SSRT100699 rev.1
HP Business Availability Center (BAC) and Business Service Management (BSM), Remote Unauthorized Access to Sensitive Information

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: RHSA-2010-0376
Critical: JBoss Enterprise Application Platform 4.2.0.CP09 update

Source: CCN
Type: RHSA-2010-0377
Critical: JBoss Enterprise Application Platform 4.3.0.CP08 update

Source: CCN
Type: RHSA-2010-0378
Critical: JBoss Enterprise Application Platform 4.2.0.CP09 update

Source: CCN
Type: RHSA-2010-0379
Critical: JBoss Enterprise Application Platform 4.3.0.CP08 update

Source: CCN
Type: SA39563
Red Hat JBoss Enterprise Application Platform Three Security Issues

Source: CCN
Type: SA47648
HP Business Availability Center / Business Service Management Multiple Security Issues

Source: CCN
Type: SA54255
HP Network Node Manager i (NNMi) Multiple Vulnerabilities

Source: CCN
Type: SECTRACK ID: 1023918
JBoss Enterprise Application Platform Bugs Let Remote Users Bypass Authentication and Access Potentially Sensitive Information

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: JBoss Web site
JBoss Enterprise Application Platform

Source: CCN
Type: BID-39710
JBoss Enterprise Application Platform Multiple Vulnerabilities

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: Vendor Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: XF
Type: UNKNOWN
jboss-status-servlet-information-disclosure(58149)

Source: CCN
Type: HP Security Bulletin HPSBMU02894 rev.1
HP Network Node Manager I (NNMi) for HP-UX, Linux, Solaris, and Windows, Remote Denial of Service (DoS), Unauthorized Access, Execution of Arbitrary Code

Source: CCN
Type: Packet Storm Security [02-09-2018]
JBoss 4.2.x / 4.3.x Information Disclosure

Source: CCN
Type: RHSA-2010:0376-1
JBoss Enterprise Application Platform 4.2.0.CP09 update

Source: secalert@redhat.com
Type: Vendor Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Vendor Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Vendor Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Vendor Advisory
secalert@redhat.com

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [02-10-2018]

Source: secalert@redhat.com
Type: UNKNOWN
secalert@redhat.com

Source: CCN
Type: Rapid7 Vulnerability and Exploit Database [05-30-2018]
JBoss Status Servlet Information Gathering

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:redhat:jboss_enterprise_application_platform:4.2:*:*:*:*:*:*:*
  • OR cpe:/a:redhat:jboss_enterprise_application_platform:4.3:*:*:*:*:*:*:*
  • AND
  • cpe:/a:hp:business_availability_center:8.01:*:*:*:*:*:*:*
  • OR cpe:/a:hp:business_availability_center:8.05:*:*:*:*:*:*:*
  • OR cpe:/a:hp:network_node_manager_i:9.0:*:*:*:*:*:*:*
  • OR cpe:/a:hp:business_availability_center:8.06:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    redhat jboss enterprise application platform 4.2
    redhat jboss enterprise application platform 4.3
    hp business availability center 8.01
    hp business availability center 8.05
    hp network node manager i 9.0
    hp business availability center 8.06