CVE-2010-2474
published 2010-08-10CVE-2010-2474: JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a…
PriorityP415low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
0.90%
55.7th percentile
JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_service_bus | <= 4.7 | — |
| redhat | jboss_enterprise_service_bus | — | — |
| redhat | jboss_enterprise_service_bus | — | — |
| redhat | jboss_enterprise_service_bus | — | — |
| redhat | jboss_enterprise_service_bus | — | — |
| redhat | jboss_enterprise_service_bus | — | — |
| redhat | jboss_enterprise_service_bus | — | — |
| redhat | jboss_enterprise_service_bus | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
JBoss ESB privilege escalation in cross-domain contexts
vendor_redhat·2010-06-11·CVSS 3.5
CVE-2010-2474 [LOW] JBoss ESB privilege escalation in cross-domain contexts
JBoss ESB privilege escalation in cross-domain contexts
JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.
Statement: This issue was fixed by the 5.0.2 release of the JBoss Enterprise SOA Platform, available for download from the Red Hat Customer Portal:
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=soaplatform&downloadType=distributions&version=5.0.2+GA
The JBoss Enterprise SOA Platform 5.0.2 Release Notes are available from http://www.redhat.com/docs/en-US/JBoss_SOA_Platform/5.0.2/html/5.0.2_Release_Notes/index.html
GHSA
GHSA-gq7m-hr2g-v7j8: JBoss Enterprise Service Bus (ESB) before 4
ghsa_unreviewed·2022-05-17
CVE-2010-2474 [LOW] CWE-20 GHSA-gq7m-hr2g-v7j8: JBoss Enterprise Service Bus (ESB) before 4
JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.
No detection rules found.
No public exploits indexed.
http://secunia.com/advisories/40568http://secunia.com/advisories/40681http://www.redhat.com/docs/en-US/JBoss_SOA_Platform/5.0.2/html/5.0.2_Release_Notes/index.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=609442https://jira.jboss.org/browse/JBESB-3345http://secunia.com/advisories/40568http://secunia.com/advisories/40681http://www.redhat.com/docs/en-US/JBoss_SOA_Platform/5.0.2/html/5.0.2_Release_Notes/index.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=609442https://jira.jboss.org/browse/JBESB-3345
2010-08-10
Published