Информационная безопасность
[RU] switch to
English Version



CVECVE-2007-1036
СтатусCandidate
ОписаниеThe default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
ВажностьHigh
CVSS score10
CVSS vector(AV:R/AC:L/Au:NR/C:C/I:C/A:C/B:N)
PhaseAssigned (20.02.2007)
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1036
ReferencesBUGTRAQ : 20070220 Jboss vulnerability
 BUGTRAQ : 20070220 Re: Jboss vulnerability
 BUGTRAQ : 20070220 Re: Jboss vulnerability
 CERT-VN : VU#632656
 MISC : http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss
 MISC : http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureThe...
 SECTRACK : 1017677
 XF : jboss-admin-unauth-access(32596)
SecurityVulns:Небезопасная конфигурация по-умолчанию в JBoss (insecure defaults)

О сайте | Условия использования
© SecurityVulns, 3APA3A, Владимир Дубровин
Нижний Новгород

 
 



Rating@Mail.ru
test server