## https://sploitus.com/exploit?id=SAINT:C763DDFFB7CB523379D9F2F7586FB6F3
Added: 07/26/2006
CVE: [CVE-2006-3733](<https://vulners.com/cve/CVE-2006-3733>)
BID: [19075](<http://www.securityfocus.com/bid/19075>)
OSVDB: [27419](<http://www.osvdb.org/27419>)
### Background
The [Cisco Security Monitoring, Analysis, and Response System](<http://www.cisco.com/en/US/products/ps6241/index.html>) (CS-MARS) recognizes and correlates network attacks.
### Problem
CS-MARS includes the JBoss web application server with insufficient access control to the `**jmx-console**` component. This component can be used by a remote attacker to execute arbitrary commands.
### Resolution
Upgrade to CS-MARS 4.2.1 or higher or apply the upgrade referenced in [Cisco Security Advisory cisco-sa-20060719-mars](<http://www.cisco.com/warp/public/707/cisco-sa-20060719-mars.shtml>).
### References
<http://www.securityfocus.com/archive/1/440641>
### Platforms
cs-mars