Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.142595
Categoría:Web application abuses
Título:JBoss Console and Web Management Misconfiguration Vulnerability
Resumen:The default configuration of JBoss does not restrict access to the console and; web management interfaces, which allows remote attackers to bypass authentication and gain administrative access; via direct requests.
Descripción:Summary:
The default configuration of JBoss does not restrict access to the console and
web management interfaces, which allows remote attackers to bypass authentication and gain administrative access
via direct requests.

Solution:
As stated by Red Hat, the JBoss AS console manager should always be secured
prior to deployment, as directed in the JBoss Application Server Guide and release notes. By default, the JBoss
AS installer gives users the ability to password protect the console manager. If the user did not use the
installer, the raw JBoss services will be in a completely unconfigured state and these steps should be performed
manually. See the referenced advisories for mitigation steps.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2007-1036
Bugtraq: 20070220 Jboss vulnerability (Google Search)
http://www.securityfocus.com/archive/1/460597/100/0/threaded
Bugtraq: 20070220 Re: Jboss vulnerability (Google Search)
http://www.securityfocus.com/archive/1/460605/100/0/threaded
http://www.securityfocus.com/archive/1/460695/100/0/threaded
CERT/CC vulnerability note: VU#632656
http://www.kb.cert.org/vuls/id/632656
http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureJBoss
http://wiki.jboss.org/wiki/Wiki.jsp?page=SecureTheJmxConsole
http://osvdb.org/33744
http://www.securitytracker.com/id?1017677
XForce ISS Database: jboss-admin-unauth-access(32596)
https://exchange.xforce.ibmcloud.com/vulnerabilities/32596
CopyrightCopyright (C) 2019 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.