This application requires Javascript for optimal performance.

JBoss.Jmxconsole.Deployer

Release Date

Oct 26, 2011

Severity

medium

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Description

This indicates detection of a attempt to exploit a vulnerability in JBoss 4.x, 5.x and 6.x.

The vulnerability is in the JBoss Web JMX Console services that can be used to deploy a new application via the "HtmlAdaptor" servlet.

Affected Products

JBoss 4.x, 5.x and 6.x both on Windows and Linux.

Recommended Actions

Upgrade to the latest version, available from the web site.
http://www.jboss.org/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2010-0738

Reference/s

http://www.redteam-pentesting.de/publications/jboss
http://www.securityfocus.com/bid/39710 (BugTraq)

Reference: VID-29534