peter bassill · operator
$ cve CVE-2007-1036 JSON

CVE-2007-1036 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 82.3% (pctl 100)

Patch early

A public exploit exists.

Description

The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS82.26% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2007-02-21
Last modified2026-06-16

Affected (1)

VendorProduct
jbossjboss application server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD