VDB
CVE-2007-1036
CVE-2007-1036
PUBLISHED
CVSS 7.5 HIGH
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
EPSS 90.14% · 99.6th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
90.14%
99.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| jboss | jboss_application_server | |
| n/a | n/a | * |
Timeline
- Feb 21, 2007 CVE Published
- Oct 19, 2010 PoC Published
- Sep 5, 2012 PoC Published
- Sep 28, 2012 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
References
- http://osvdb.org/33744 technical
- http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss url
- 1017677 vdb
- http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole url
- jboss-admin-unauth-access(32596) vdb
- VU#632656 third-party-advisory
- 20070220 Jboss vulnerability mailing-list
- 20070220 Re: Jboss vulnerability mailing-list
- 20070220 Re: Jboss vulnerability mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2007-1036 advisory