Resolving "JBoss Web Console is Accessible to Unauthenticated Remote Users" vulnerability
Posted
by
IAmJeff
on Super User
See other posts from Super User
or by IAmJeff
Published on 2014-08-22T21:45:03Z
Indexed on
2014/08/22
22:24 UTC
Read the original article
Hit count: 554
Our security team has determined there is a vulnerability in one of our systems. We are using version JBoss 5.1.0GA on RHEL 5.10.
Vulnerability description:
JBoss Web Console is Accessible to Unauthenticated Remote Users
Yes, this looks familiar. Refer to Question 501417. I do not find the answer there complete. Can someone (or multiple someones) answer
- Does a newer version of JBoss fix this vulnerability?
- Are there links describing, in more detail, manual modification of JBoss configuration files to resolve the issue?
- Are there others options to remediate this vulnerability?
Why don't I find the other answer complete? I'm not at all familiar with JBoss, so this answer seems a bit too simple.
The web-console.war contains commented-out templates for basic security in its WEB-INF/web.xml as well as commented-out setup for a security domain in WEB-INF/jboss-web.xml.
Just uncomment those basic security blocks and restart? Is there anything else I need to include?
This seems generic. Do I need to include anything about my environment, such as absolute paths, etc.? Am I making this too complicated?
© Super User or respective owner