JBoss provides a range of enterprise Java application servers and middleware components—including the JBoss Application Server, Enterprise Application Platform, and related frameworks—that host business-critical applications in complex integration environments. The vendor's disclosures concentrate on application-layer and input-handling vulnerabilities such as cross-site request forgery, SQL injection, and improper input validation, alongside occasional parser-related weaknesses, and frequently acquire public exploit code. Current severity, in-the-wild exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jboss over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1036HIGH The default configuration of JBoss does not restrict access to the (1) console and (2) web management interfaces, which allows remote attackers to bypass authentication and gain ad | Feb 21, 2007 | 7.5 | 83 | NO | YES |
CVE-2008-3273MEDIUM JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed | Aug 10, 2008 | 5.0 | 48 | NO | YES |
CVE-2003-0845HIGH Unknown vulnerability in the HSQLDB component in JBoss 3.2.1 and 3.0.8 on Java 1.4.x platforms, when running in the default configuration, allows remote attackers to conduct unauth | Nov 17, 2003 | 7.5 | 40 | NO | YES |
CVE-2018-1041HIGH A vulnerability was found in the way RemoteMessageChannel, introduced in jboss-remoting versions 3.3.10, reads from an empty buffer. An attacker could use this flaw to cause denial | Feb 15, 2018 | 7.5 | 35 | NO | YES |
CVE-2005-2006MEDIUM JBOSS 3.2.2 through 3.2.7 and 4.0.2 allows remote attackers to obtain sensitive information via a GET request (1) with a "%." (percent dot), which reveals the installation path or | Jun 17, 2005 | 5.0 | 33 | NO | YES |
CVE-2006-5750HIGH Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows remote authenticated users to read or modif | Nov 27, 2006 | 7.5 | 27 | NO | NO |
CVE-2016-2094HIGH The HTTPS NIO Connector allows remote attackers to cause a denial of service (thread consumption) by opening a socket and not sending an SSL handshake, aka a read-timeout vulnerabi | May 6, 2016 | 7.5 | 25 | NO | NO |
CVE-2007-6433HIGH The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to inject and execute arbitrary EJBQL commands vi | Dec 18, 2007 | 7.5 | 20 | NO | NO |
CVE-2007-1157HIGH Cross-site request forgery (CSRF) vulnerability in jmx-console/HtmlAdaptor in JBoss allows remote attackers to perform privileged actions as administrators via certain MBean operat | Mar 2, 2007 | 7.6 | 19 | NO | NO |
CVE-2005-2158HIGH A regression error in the embedded HSQLDB in JBoss jBPM 2.0 allows remote attackers to execute arbitrary comands, a re-introduction of a vulnerability that was originally identifie | Jul 6, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jboss.
Media articles that mention a CVE ID that affects a product developed by Jboss — matched by CVE ID, not by vendor name.