Loading vulnerability details…
CVSS v3.1
N/A
EPSS
81.77%
Published
Feb 21, 2007
Modified
Jun 16, 2026
Public PoC / Exploit (3)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain administrative access via direct requests.
Weaknesses (CWE)
Affected Products (1)
References (18)