CVE-2007-1036
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
- Affected products
- Jboss
- Jboss Jboss Application Server
- All versions
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 81.8% (100th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2007-02-21
CVE-2007-1036 at NVD
6 known exploits for CVE-2007-1036
Proof-of-concept code and exploit modules indexed by Sploitus
JBoss DeploymentFileRepository WAR Deployment
JBoss - DeploymentFileRepository WAR Deployment (via JMXInvokerServlet) (Metasploit)
JBoss DeploymentFileRepository WAR Deployment
JBoss DeploymentFileRepository WAR Deployment (via JMXInvokerServlet)
JBoss JMX Console Deployer Upload and Execute
JBoss JMX - Console Deployer Upload and Execute (Metasploit)