Showing 3 vulnerabilities on this page for JBoss

Signals CISA KEV Ransomware Nuclei
Red Hat vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

A missing permission check was found in The CLI in JBoss Operations Network before 2.3.1 does not properly check permissions, which allows JBoss ON users to perform management tasks and configuration changes with the privileges of the administrator user.

CWE-732Oct 30, 2019
CVSS8.0v3.1EPSS0.533%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Red Hat JBoss Information Disclosure Vulnerability

The Web Console (aka web-console) in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to obtain sensitive information via an unspecified request that uses a different method.

CWE-264CWE-749Apr 28, 2010
CVSS7.5v3.1EPSS62.3%PoCs1SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX

Red Hat JBoss Authentication Bypass Vulnerability

The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 performs access control only for the GET and POST methods, which allows remote attackers to send requests to this application's GET handler by using a different method.

CWE-264CWE-749Apr 28, 2010
CVSS5.3v3.1EPSS79.4%PoCs11SignalsListed in CISA KEVKnown ransomware useNo Nuclei templatesSTIX