Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2010-4265

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Red Hat JBoss Enterprise Application Platform(EAP)是美国红帽(Red Hat)公司的一套开源的、基于J2EE的中间件平台。该平台主要用于构建、部署和托管Java应用程序与服务。 Red Hat JBoss Enterprise Application Platform 4.3至4.3.0.CP09版本存在安全漏洞。远程攻击者可以通过建立bisocket控制连接TCP会话,并不立即发送任意应用程序数据,导致拒绝服务(守护进程崩溃)。

AI Predicted 7.5 Difficulty: Trivial EPSS 2.13% · P80
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2010-4265

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
The org.jboss.remoting.transport.bisocket.BisocketServerInvoker$SecondaryServerSocketThread.run method in JBoss Remoting 2.2.x before 2.2.3.SP4 and 2.5.x before 2.5.3.SP2 in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3 through 4.3.0.CP09 allows remote attackers to cause a denial of service (daemon outage) by establishing a bisocket control connection TCP session, and then not sending any application data, related to a missing CVE-2010-3862 patch. NOTE: this can be considered a duplicate of CVE-2010-3862 because a missing patch should not be assigned a separate CVE identifier.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Red Hat JBoss Enterprise Application Platform 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Red Hat JBoss Enterprise Application Platform(EAP)是美国红帽(Red Hat)公司的一套开源的、基于J2EE的中间件平台。该平台主要用于构建、部署和托管Java应用程序与服务。 Red Hat JBoss Enterprise Application Platform 4.3至4.3.0.CP09版本存在安全漏洞。远程攻击者可以通过建立bisocket控制连接TCP会话,并不立即发送任意应用程序数据,导致拒绝服务(守护进程崩溃)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2010-4265

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2010-4265

登录查看更多情报信息。

Vendor Advisories for CVE-2010-4265 (2)

Other References for CVE-2010-4265 (4)

Same Patch Batch · n/a · 2010-12-30 · 38 CVEs total

CVE-2010-4161 Red Hat Enterprise Linux net/ipv4/udp.c文件资源管理错误漏洞
CVE-2010-4638 JQuarks函数SQL注入漏洞
CVE-2010-4639 Intendance MySource Matrix index.php文件SQL注入漏洞
CVE-2010-4640 XWiki Watch 多个跨站脚本攻击漏洞
CVE-2010-4641 XWiki Enterprise SQL注入漏洞
CVE-2010-4642 XWiki跨站脚本攻击漏洞
CVE-2010-3848 Linux kernel econet_sendmsg函数栈缓冲区错误漏洞
CVE-2010-3849 Linux kernel econet_sendmsg函数资源管理错误漏洞
CVE-2010-3850 Linux kernel ec_dev_ioctl函数权限许可和访问控制问题漏洞
CVE-2010-4158 Linux kernel sk_run_filter函数信息泄露漏洞
CVE-2010-4637 Finalcut feedlist/handler_image.php文件跨站脚本攻击漏洞
CVE-2010-4258 Linux kernel kernel/exit.c文件权限许可和访问控制问题漏洞
CVE-2010-4276 LiveZilla "livezilla"跨站脚本攻击漏洞
CVE-2010-4321 Novell iPrint Client ienipp.ocx ActiveX控件栈缓冲区溢出漏洞
CVE-2010-4342 Linux kernel aun_incoming函数资源管理错误漏洞
CVE-2010-4352 D-BUS 资源管理错误漏洞
CVE-2010-4507 Clear iSpot和ClearSpot多个跨站请求伪造漏洞
CVE-2010-4622 IBM Tivoli Access Manager路径遍历漏洞
CVE-2010-4623 IBM Tivoli Access Manager WebSEAL资源管理错误漏洞
CVE-2010-4628 MyBB member.php文件拒绝服务漏洞

Showing top 20 of 38 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2010-4265

No comments yet


Leave a comment