← All CVEs

CVE-2007-1036

high · 7.5

The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.

7.5
CVSS
82.3%
EPSS (exploit prob.)
100th
EPSS percentile
2007-02-21
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
jbossjboss_application_serverall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-1036