Disclosure summary
Unauthenticated access to the JBoss Application Server Web Console (/web-console) is blocked by default. However, it was found that this block was incomplete, and only blocked GET and POST HTTP verbs. A remote attacker could use this flaw to gain access to sensitive information.
CISA remediation guidance
Apply updates per vendor instructions.
Original records & references
PUBLISHED 2022-05-25T00:00:00-04:00
MODIFIED 2022-05-25T00:00:00-04:00
INGESTED 2026-10-06T11:42:58-04:00