VulnerabilityModified
CVE-2007-1036
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
HIGH 7.5EPSS 81.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 81.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 81.77% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- jboss/jboss application server
- Source
- cve@mitre.org
References
- http://osvdb.org/33744
- http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss
- http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole
- http://www.kb.cert.org/vuls/id/632656US Government Resource
- http://www.securityfocus.com/archive/1/460597/100/0/threaded
- http://www.securityfocus.com/archive/1/460605/100/0/threaded
- http://www.securityfocus.com/archive/1/460695/100/0/threaded
- http://www.securitytracker.com/id?1017677
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32596
- http://osvdb.org/33744
- http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss
- http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole
- http://www.kb.cert.org/vuls/id/632656US Government Resource
- http://www.securityfocus.com/archive/1/460597/100/0/threaded
- http://www.securityfocus.com/archive/1/460605/100/0/threaded
- http://www.securityfocus.com/archive/1/460695/100/0/threaded
- http://www.securitytracker.com/id?1017677
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32596
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.