First published: Wed Feb 21 2007(Updated: )
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
JBoss Application Server | ||
Red Hat JBoss Application Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1036 has a high severity level due to the potential for unauthorized access to the JBoss administrative interfaces.
To fix CVE-2007-1036, update your JBoss configuration to enforce authentication on the console and web management interfaces.
CVE-2007-1036 affects systems running Red Hat JBoss Application Server with default configurations.
Yes, CVE-2007-1036 can be exploited remotely, allowing attackers to gain administrative access without authentication.
Yes, a workaround for CVE-2007-1036 is to manually configure user authentication for the affected interfaces in JBoss.