Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.142595
Kategorie:Web Servers
Titel:Red Hat JBoss Application Server (AS) Console and Web Management Misconfiguration Vulnerability - Active Check
Zusammenfassung:The default configuration of Red Hat JBoss Application Server; (AS) does not restrict access to the console and web management interfaces, which allows remote; attackers to bypass authentication and gain administrative access via direct requests.
Beschreibung:Summary:
The default configuration of Red Hat JBoss Application Server
(AS) does not restrict access to the console and web management interfaces, which allows remote
attackers to bypass authentication and gain administrative access via direct requests.

Solution:
As stated by Red Hat, the JBoss AS console manager should
always be secured prior to deployment, as directed in the JBoss Application Server Guide and
release notes. By default, the JBoss AS installer gives users the ability to password protect the
console manager. If the user did not use the installer, the raw JBoss services will be in a
completely unconfigured state and these steps should be performed manually. See the referenced
advisories for mitigation steps.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2007-1036
Bugtraq: 20070220 Jboss vulnerability (Google Search)
http://www.securityfocus.com/archive/1/460597/100/0/threaded
Bugtraq: 20070220 Re: Jboss vulnerability (Google Search)
http://www.securityfocus.com/archive/1/460605/100/0/threaded
http://www.securityfocus.com/archive/1/460695/100/0/threaded
CERT/CC vulnerability note: VU#632656
http://www.kb.cert.org/vuls/id/632656
http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss
http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole
http://osvdb.org/33744
http://www.securitytracker.com/id?1017677
XForce ISS Database: jboss-admin-unauth-access(32596)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32596
CopyrightCopyright (C) 2019 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.