CVE-2010-2474: Input Validation
A low impact privilege escalation flaw in the JBoss ESB component was found whereby the execution of a service with a different domain could, potentially, have resulted in the pipeline being run with different sets of credentials, (one set from the first domain if the request were still valid and a second set from the other domain if it had expired).
Other sources
JBoss Enterprise Service Bus (ESB) before 4.7 CP02 in JBoss Enterprise SOA Platform before 5.0.2 does not properly consider the security domain with which a service is secured, which might allow remote attackers to gain privileges by executing a service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2474?
CVE-2010-2474 has a low severity rating due to its limited potential for impact.
How do I fix CVE-2010-2474?
To fix CVE-2010-2474, it is recommended to upgrade JBoss ESB to version 4.8 or later.
Which JBoss versions are affected by CVE-2010-2474?
CVE-2010-2474 affects JBoss ESB versions up to 4.7 and specific versions like 4.0, 4.2, 4.2.1, 4.3, 4.4, 4.5, and 4.6.
Can CVE-2010-2474 lead to privilege escalation?
Yes, CVE-2010-2474 allows for low impact privilege escalation under certain conditions.
Where can I find more information about CVE-2010-2474?
For more information about CVE-2010-2474, refer to bug tracking systems or security advisories related to JBoss.