CVE-2007-1036
high · 7.5The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
7.5
CVSS
82.3%
EPSS (exploit prob.)
100th
EPSS percentile
2007-02-21
Published
AV:N/AC:L/Au:N/C:P/I:P/A:P
Weaknesses
CWE-264
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| jboss | jboss_application_server | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://osvdb.org/33744
- http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss
- http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole
- http://www.kb.cert.org/vuls/id/632656
- http://www.securityfocus.com/archive/1/460597/100/0/threaded
- http://www.securityfocus.com/archive/1/460605/100/0/threaded
- http://www.securityfocus.com/archive/1/460695/100/0/threaded
- http://www.securitytracker.com/id?1017677
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32596
- http://osvdb.org/33744
- http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss
- http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole
- http://www.kb.cert.org/vuls/id/632656
- http://www.securityfocus.com/archive/1/460597/100/0/threaded
- http://www.securityfocus.com/archive/1/460605/100/0/threaded
- http://www.securityfocus.com/archive/1/460695/100/0/threaded
- http://www.securitytracker.com/id?1017677
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32596
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-1036