The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests
Published Feb 21, 2007
7.5
HIGHCVSS 2.0
EPSS 82.26%
Description
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
Affected products
No data.
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
The JBoss AS console manager should always be secured prior to deployment, as directed in the JBoss Application Server Guide and release notes. By default, the JBoss AS installer gives users the ability to password protect the console manager. If the user did not use the installer, the raw JBoss services will be in a completely unconfigured state and these steps should be performed manually: http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (13 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 82.26% (0.82256) | 99.65th | v5 (v2026.06.15) |
| Jun 15, 2026 | 81.83% (0.81832) | 99.60th | v5 (v2026.06.15) |
| Mar 17, 2025 | 89.76% (0.89760) | 99.55th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.76% (0.96763) | 99.73th | v3 (v2023.03.01) |
| Jul 16, 2024 | 96.76% (0.96763) | 99.69th | v3 (v2023.03.01) |
| May 27, 2024 | 96.59% (0.96590) | 99.62th | v3 (v2023.03.01) |
| Apr 18, 2024 | 96.76% (0.96763) | 99.66th | v3 (v2023.03.01) |
| Dec 26, 2023 | 96.85% (0.96851) | 99.63th | v3 (v2023.03.01) |
| Nov 18, 2023 | 96.71% (0.96714) | 99.56th | v3 (v2023.03.01) |
| Jul 26, 2023 | 97.09% (0.97093) | 99.66th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.06% (0.97061) | 99.56th | v3 (v2023.03.01) |
| Mar 6, 2023 | 80.10% (0.80096) | 99.51th | v2 (v2022.01.01) |
| Feb 4, 2022 | 80.10% (0.80096) | 99.41th | v2 (v2022.01.01) |
References (12)
- http://osvdb.org/33744 vdb-entryx_refsource_OSVDB
- http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss x_refsource_MISC
- http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole x_refsource_MISC
- http://www.kb.cert.org/vuls/id/632656 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.securityfocus.com/archive/1/460597/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/460605/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/460695/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securitytracker.com/id?1017677 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2007-1036 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32596 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2007-1036
- https://www.cve.org/CVERecord?id=CVE-2007-1036
| Link | Providers | Tags |
|---|---|---|
| http://osvdb.org/33744 | vdb-entryx_refsource_OSVDB | |
| http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss | x_refsource_MISC | |
| http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole | x_refsource_MISC | |
| http://www.kb.cert.org/vuls/id/632656 | third-party-advisoryx_refsource_CERT-VNUS Government Resource | |
| http://www.securityfocus.com/archive/1/460597/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/archive/1/460605/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/archive/1/460695/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securitytracker.com/id?1017677 | vdb-entryx_refsource_SECTRACK | |
| https://access.redhat.com/security/cve/CVE-2007-1036 | Vendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/32596 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2007-1036 | ||
| https://www.cve.org/CVERecord?id=CVE-2007-1036 |
Change history (0)
No recorded changes yet.