Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.142595
Category:Web Servers
Title:Red Hat JBoss Application Server (AS) Console and Web Management Misconfiguration Vulnerability - Active Check
Summary:The default configuration of Red Hat JBoss Application Server; (AS) does not restrict access to the console and web management interfaces, which allows remote; attackers to bypass authentication and gain administrative access via direct requests.
Description:Summary:
The default configuration of Red Hat JBoss Application Server
(AS) does not restrict access to the console and web management interfaces, which allows remote
attackers to bypass authentication and gain administrative access via direct requests.

Solution:
As stated by Red Hat, the JBoss AS console manager should
always be secured prior to deployment, as directed in the JBoss Application Server Guide and
release notes. By default, the JBoss AS installer gives users the ability to password protect the
console manager. If the user did not use the installer, the raw JBoss services will be in a
completely unconfigured state and these steps should be performed manually. See the referenced
advisories for mitigation steps.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-1036
Bugtraq: 20070220 Jboss vulnerability (Google Search)
http://www.securityfocus.com/archive/1/460597/100/0/threaded
Bugtraq: 20070220 Re: Jboss vulnerability (Google Search)
http://www.securityfocus.com/archive/1/460605/100/0/threaded
http://www.securityfocus.com/archive/1/460695/100/0/threaded
CERT/CC vulnerability note: VU#632656
http://www.kb.cert.org/vuls/id/632656
http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss
http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole
http://osvdb.org/33744
http://www.securitytracker.com/id?1017677
XForce ISS Database: jboss-admin-unauth-access(32596)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32596
CopyrightCopyright (C) 2019 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.