Vulnerability Details CVE-2010-2474
JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 48.5%
CVSS Severity
CVSS v2 Score 3.5
Products affected by CVE-2010-2474
-
cpe:2.3:a:redhat:jboss_enterprise_service_bus:4.0
-
cpe:2.3:a:redhat:jboss_enterprise_service_bus:4.2
-
cpe:2.3:a:redhat:jboss_enterprise_service_bus:4.2.1
-
cpe:2.3:a:redhat:jboss_enterprise_service_bus:4.3
-
cpe:2.3:a:redhat:jboss_enterprise_service_bus:4.4
-
cpe:2.3:a:redhat:jboss_enterprise_service_bus:4.5
-
cpe:2.3:a:redhat:jboss_enterprise_service_bus:4.6
-
cpe:2.3:a:redhat:jboss_enterprise_service_bus:4.7
-
cpe:2.3:a:redhat:jboss_enterprise_soa_platform:4.2.0
-
cpe:2.3:a:redhat:jboss_enterprise_soa_platform:4.3.0
-
cpe:2.3:a:redhat:jboss_enterprise_soa_platform:5.0.0
-
cpe:2.3:a:redhat:jboss_enterprise_soa_platform:5.0.1