Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-1036
Description:The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
Test IDs: 1.3.6.1.4.1.25623.1.0.142595  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-1036
Bugtraq: 20070220 Jboss vulnerability (Google Search)
http://www.securityfocus.com/archive/1/460597/100/0/threaded
Bugtraq: 20070220 Re: Jboss vulnerability (Google Search)
http://www.securityfocus.com/archive/1/460605/100/0/threaded
Bugtraq: 20070220 Re: Jboss vulnerability (Google Search)
http://www.securityfocus.com/archive/1/460695/100/0/threaded
CERT/CC vulnerability note: VU#632656
http://www.kb.cert.org/vuls/id/632656
http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss
http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole
http://osvdb.org/33744
http://www.securitytracker.com/id?1017677
XForce ISS Database: jboss-admin-unauth-access(32596)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32596




© 1998-2025 E-Soft Inc. All rights reserved.