CVE-2010-0738 is an authorization bypass in the JMX-Console web application in Red Hat JBoss Enterprise Application Platform 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08. The application applies access-control checks only to HTTP GET and POST requests. A remote requester can use a different HTTP method to cause the application's GET handler to process a request without the intended method-specific access control.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
This repository contains a single Metasploit auxiliary module targeting JBoss Application Server's JMX Console DeploymentFileRepository vulnerability (CVE-2010-0738). The module allows an attacker to upload and deploy an arbitrary WAR file to the target server by abusing the DeploymentFileRepository class, resulting in remote code execution. The exploit works by first uploading a JSP stager, which is then used to deploy the attacker's WAR file. The module supports both deployment and cleanup (undeploy) actions. The main file is written in Ruby and leverages Metasploit's HTTP and JBoss mixins. The exploit requires the attacker to supply a WAR file (which can contain any payload, such as a webshell or reverse shell) and the target's address and port. The module is operational and provides a practical method for remote code execution on vulnerable JBoss servers.
This repository contains a single Metasploit module: 'jboss_bshdeployer.rb', which exploits a vulnerability (CVE-2010-0738) in JBoss Application Server's JMX Console. The exploit targets servers with an exposed 'jmx-console' application, using the BSHDeployer's createScriptDeployment() method to upload and deploy a malicious WAR file. The module supports multiple platforms (Java, Linux, Windows) and allows the attacker to specify or randomly generate the application and JSP names. The payload is a WAR file containing a JSP, which can be any Metasploit-supported payload (e.g., reverse shell). The exploit proceeds by uploading the WAR, executing the payload via an HTTP request, and then attempting to clean up by deleting the deployed WAR. The main attack vector is network-based, requiring HTTP(S) access to the target's JMX Console. The module is weaponized, allowing for easy payload customization and automated exploitation.
This repository contains a single Metasploit auxiliary module (modules/auxiliary/admin/http/jboss_bshdeployer.rb) that targets JBoss Application Servers with an exposed 'jmx-console' application. The module exploits CVE-2010-0738 by using the BSHDeployer's createScriptDeployment() method to upload and deploy a user-supplied WAR file (Java web application) to the server. The module supports two actions: 'Deploy' (to upload and deploy the payload) and 'Undeploy' (to remove the deployed payload). The exploit requires the attacker to provide a WAR file, which is then base64-encoded and delivered to the target. The main attack vector is network-based, targeting the HTTP interface of the JBoss server (default port 8080). The module is operational and can be used to achieve remote code execution on vulnerable JBoss servers. The only file in the repository is the Metasploit module itself, written in Ruby.
This repository contains a single Metasploit exploit module targeting JBoss Application Server's DeploymentFileRepository class (CVE-2010-0738). The exploit abuses the ability to upload and deploy arbitrary JSP files via HTTP requests, which are then used to deploy a malicious WAR file containing a user-selected payload (such as a Meterpreter shell). The module supports automatic and manual target selection for Java, Linux, and Windows platforms. It interacts with the target over HTTP (default port 8080) and uses randomized names for the deployed files to evade detection. The exploit includes cleanup routines to remove the deployed WAR and stager files after execution. The main entry point is the Ruby file 'modules/exploits/multi/http/jboss_deploymentfilerepository.rb', which is structured according to Metasploit conventions and leverages Metasploit's payload generation and HTTP client libraries. The module is operational and can be used to achieve remote code execution on vulnerable JBoss servers.
This repository contains a single Metasploit module: 'jboss_maindeployer.rb', which exploits vulnerabilities in JBoss Application Server's jmx-console (CVE-2007-1036 and CVE-2010-0738). The exploit works by uploading a malicious WAR file to the target server using the MainDeployer functionality exposed via the jmx-console. The module sets up a temporary HTTP server to serve the WAR payload, which the target JBoss server fetches and deploys, resulting in remote code execution. The exploit supports multiple platforms (Java, Linux, Windows) and can automatically detect the target's platform and architecture. The module allows for customization of the payload, application base name, JSP name, and HTTP method (to exploit different CVEs). The main fingerprintable endpoints are the '/jmx-console' path and the '/HtmlAdaptor' MBean query. The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads for post-exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication-bypass vulnerability affecting the JBoss Application Server administrative console. It permits access-control bypass through HTTP verb tampering, potentially exposing protected management endpoints.
A remote code execution vulnerability in JBoss that remains relevant due to persistent exposure of vulnerable systems.
An older vulnerability used by Threat Group 3390 ("Emissary Panda") to compromise targets as part of watering-hole driven intrusions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.