Описание
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
Ссылки
- US Government Resource
- US Government Resource
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:jboss:jboss_application_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.90143
Критический
7.5 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
почти 4 года назад
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
EPSS
Процентиль: 100%
0.90143
Критический
7.5 High
CVSS2
Дефекты
CWE-264