VDB
CVE-2007-1354
CVE-2007-1354
PUBLISHED
CVSS 6 MEDIUM
The Access Control functionality (JMXOpsAccessControlFilter) in JMX Console in JBoss Application Server 4.0.2 and 4.0.5 before 20070416 uses a member variable to store the roles of the current user, which allows remote authenticated administrators to trigger a race condition and gain privileges by logging in during a session by a more privileged administrator, as demonstrated by privilege escalation from Read Mode to Write Mode.
EPSS 1.49% · 72.1th percentile
Risk Scores
CVSS 2.0
6
EPSS Score
1.49%
72.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| jboss | jboss_application_server | 4.0.5_cp01, 4.0.2.ga_cp03, 4.0.5.ga |
| n/a | n/a | n/a |
Timeline
- Jul 27, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score