cbcvebase.
CVE-2010-2474
published 2010-08-10

CVE-2010-2474: JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a…

PriorityP415low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
0.90%
55.7th percentile
JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.

Affected

12 ranges
VendorProductVersion rangeFixed in
redhatjboss_enterprise_service_bus<= 4.7
redhatjboss_enterprise_service_bus
redhatjboss_enterprise_service_bus
redhatjboss_enterprise_service_bus
redhatjboss_enterprise_service_bus
redhatjboss_enterprise_service_bus
redhatjboss_enterprise_service_bus
redhatjboss_enterprise_service_bus
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform
redhatjboss_enterprise_soa_platform

CVSS provenance

nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.