CVE-2007-1036 describes a critical vulnerability in the default configuration of JBoss Application Server, allowing remote attackers to bypass authentication and gain administrative access to the console and web management interfaces. With a CVSS score of 7.5 and an EPSS score indicating high exploitability, this flaw enables unauthorized individuals to directly request and manipulate administrative functions. While not on the KEV catalog, multiple Metasploit modules and ExploitDB entries confirm the existence of readily available exploit code, facilitating remote code execution and system compromise. Despite its age and high exploitability, there is no recorded community discussion or media coverage, suggesting a potential lack of awareness regarding its continued risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:jboss:jboss_application_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.