CVE-2007-1036
JBoss - DeploymentFileRepository WAR Deployment (via JMXInvokerServlet)
Severity Score
7.5
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
La configuración por defecto de JBoss no restringe el acceso a (1) la consola y (2) interfaces de gestión web, lo cual permite a atacantes remotos evitar la autenticación y obtener acceso administrativo mediante peticiones directas.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-02-20 CVE Reserved
- 2007-02-21 CVE Published
- 2010-10-19 First Exploit
- 2024-07-16 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
http://osvdb.org/33744 | Vdb Entry | |
http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss | X_refsource_misc | |
http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole | X_refsource_misc | |
http://www.kb.cert.org/vuls/id/632656 | Third Party Advisory | |
http://www.securityfocus.com/archive/1/460597/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/460605/100/0/threaded | Mailing List | |
http://www.securityfocus.com/archive/1/460695/100/0/threaded | Mailing List | |
http://www.securitytracker.com/id?1017677 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/32596 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/21080 | 2012-09-05 | |
https://www.exploit-db.com/exploits/16318 | 2010-10-19 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jboss Search vendor "Jboss" | Jboss Application Server Search vendor "Jboss" for product "Jboss Application Server" | * | - |
Affected
|