Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP "verbs". A remote attacker could use this flaw to gain access to sensitive information.
This issue has been addressed in following products: JBEAP 4.2.0 for RHEL 4 Via RHSA-2010:0376 https://rhn.redhat.com/errata/RHSA-2010-0376.html
This issue has been addressed in following products: JBEAP 4.3.0 for RHEL 4 Via RHSA-2010:0377 https://rhn.redhat.com/errata/RHSA-2010-0377.html
This issue has been addressed in following products: JBEAP 4.2.0 for RHEL 5 Via RHSA-2010:0378 https://rhn.redhat.com/errata/RHSA-2010-0378.html
This issue has been addressed in following products: JBEAP 4.3.0 for RHEL 5 Via RHSA-2010:0379 https://rhn.redhat.com/errata/RHSA-2010-0379.html