Описание
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
Ссылки
- US Government Resource
- US Government Resource
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:jboss:jboss_application_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.81775
Высокий
7.5 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
больше 4 лет назад
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
EPSS
Процентиль: 100%
0.81775
Высокий
7.5 High
CVSS2
Дефекты
CWE-264