CVE-2010-2474: Input Validation

Published Jun 30, 2010
·
Updated

A low impact privilege escalation flaw in the JBoss ESB component was found whereby the execution of a service with a different domain could, potentially, have resulted in the pipeline being run with different sets of credentials, (one set from the first domain if the request were still valid and a second set from the other domain if it had expired).

Other sources

JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.

Affected Software

22 affected components
redhat Jboss Enterprise Service Bus<=4.7
redhat Jboss Enterprise Service Bus=4.0
redhat Jboss Enterprise Service Bus=4.2
redhat Jboss Enterprise Service Bus=4.2.1
redhat Jboss Enterprise Service Bus=4.3
redhat Jboss Enterprise Service Bus=4.4
redhat Jboss Enterprise Service Bus=4.5
redhat Jboss Enterprise Service Bus=4.6
redhat Jboss Enterprise Soa Platform=4.2.0
redhat Jboss Enterprise Soa Platform=4.2.0-cp01
redhat Jboss Enterprise Soa Platform=4.2.0-cp02
redhat Jboss Enterprise Soa Platform=4.2.0-cp03
redhat Jboss Enterprise Soa Platform=4.2.0-cp04
redhat Jboss Enterprise Soa Platform=4.2.0-cp05
redhat Jboss Enterprise Soa Platform=4.2.0-tp02
redhat Jboss Enterprise Soa Platform=4.3.0
redhat Jboss Enterprise Soa Platform=4.3.0-cp01
redhat Jboss Enterprise Soa Platform=4.3.0-cp02
redhat Jboss Enterprise Soa Platform=4.3.0-cp03
redhat Jboss Enterprise Soa Platform=4.3.0-cp04
redhat Jboss Enterprise Soa Platform=5.0.0
redhat Jboss Enterprise Soa Platform=5.0.1

Event History

Jun 30, 2010
Data Sourced
via Red Hat·10:21 AM
DescriptionSeverityAffected Software
Aug 9, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Aug 10, 2010
Data Sourced
12:23 PM
DescriptionWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2010-2474?

CVE-2010-2474 has a low severity rating due to its limited potential for impact.

2

How do I fix CVE-2010-2474?

To fix CVE-2010-2474, it is recommended to upgrade JBoss ESB to version 4.8 or later.

3

Which JBoss versions are affected by CVE-2010-2474?

CVE-2010-2474 affects JBoss ESB versions up to 4.7 and specific versions like 4.0, 4.2, 4.2.1, 4.3, 4.4, 4.5, and 4.6.

4

Can CVE-2010-2474 lead to privilege escalation?

Yes, CVE-2010-2474 allows for low impact privilege escalation under certain conditions.

5

Where can I find more information about CVE-2010-2474?

For more information about CVE-2010-2474, refer to bug tracking systems or security advisories related to JBoss.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203