VDB

CVE-2007-1036

CVE-2007-1036 PUBLISHED CVSS 7.5 HIGH

The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.

EPSS 90.14% · 99.6th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
90.14%
99.6th percentile

Affected Products

VendorProductVersions
jbossjboss_application_server
n/an/a*

Timeline

  • Feb 21, 2007 CVE Published
  • Oct 19, 2010 PoC Published
  • Sep 5, 2012 PoC Published
  • Sep 28, 2012 PoC Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›