Resolving "JBoss Web Console is Accessible to Unauthenticated Remote Users" vulnerability

Posted by IAmJeff on Super User See other posts from Super User or by IAmJeff
Published on 2014-08-22T21:45:03Z Indexed on 2014/08/22 22:24 UTC
Read the original article Hit count: 554

Filed under:
|

Our security team has determined there is a vulnerability in one of our systems. We are using version JBoss 5.1.0GA on RHEL 5.10.

Vulnerability description:

JBoss Web Console is Accessible to Unauthenticated Remote Users

Yes, this looks familiar. Refer to Question 501417. I do not find the answer there complete. Can someone (or multiple someones) answer

  1. Does a newer version of JBoss fix this vulnerability?
  2. Are there links describing, in more detail, manual modification of JBoss configuration files to resolve the issue?
  3. Are there others options to remediate this vulnerability?

Why don't I find the other answer complete? I'm not at all familiar with JBoss, so this answer seems a bit too simple.

The web-console.war contains commented-out templates for basic security in its WEB-INF/web.xml as well as commented-out setup for a security domain in WEB-INF/jboss-web.xml.

Just uncomment those basic security blocks and restart? Is there anything else I need to include?

This seems generic. Do I need to include anything about my environment, such as absolute paths, etc.? Am I making this too complicated?

© Super User or respective owner

Related posts about security

Related posts about jboss