Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Jboss

First CVE: Nov 17, 2003Active for: 23 yearsTotal CVEs: 14
48.3
VTI Score
High

JBoss provides a range of enterprise Java application servers and middleware components—including the JBoss Application Server, Enterprise Application Platform, and related frameworks—that host business-critical applications in complex integration environments. The vendor's disclosures concentrate on application-layer and input-handling vulnerabilities such as cross-site request forgery, SQL injection, and improper input validation, alongside occasional parser-related weaknesses, and frequently acquire public exploit code. Current severity, in-the-wild exploitation, and CVE counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Jboss over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2003
22 years ago
Most Recent CVE
Feb 15, 2018
3,081 days ago

Products(9 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-1036HIGH
The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain ad
Feb 21, 20077.583NOYES
CVE-2008-3273MEDIUM
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed
Aug 10, 20085.048NOYES
CVE-2003-0845HIGH
Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauth
Nov 17, 20037.540NOYES
CVE-2018-1041HIGH
A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial
Feb 15, 20187.535NOYES
CVE-2005-2006MEDIUM
JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which reveals the installation path or
Jun 17, 20055.033NOYES
CVE-2006-5750HIGH
Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows remote authenticated users to read or modif
Nov 27, 20067.527NONO
CVE-2016-2094HIGH
The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshake, aka a read-timeout vulnerabi
May 6, 20167.525NONO
CVE-2007-6433HIGH
The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to inject and execute arbitrary EJBQL commands vi
Dec 18, 20077.520NONO
CVE-2007-1157HIGH
Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administrators via certain MBean operat
Mar 2, 20077.619NONO
CVE-2005-2158HIGH
A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identifie
Jul 6, 20057.519NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
43%
57%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (14.3%)
Unknown12 (85.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (14.3%)
High0 (0.0%)
Unknown12 (85.7%)
User Interaction
None2 (14.3%)
Unknown12 (85.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (14.3%)
Unknown12 (85.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
14.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
28.6% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Jboss.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Jboss — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Jboss's Products

View all 2 CNAs →

Top CWEs