vendor:
JMX Console
by:
y0ug
7.5
CVSS
HIGH
Misconfigured DeploymentScanner
16
CWE
Product Name: JMX Console
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2010-0738
CPE: N/A
Metasploit:
https://www.rapid7.com/db/vulnerabilities/jboss_enterprise_application_platform-cve-2011-4085/, https://www.rapid7.com/db/vulnerabilities/jboss_enterprise_application_platform-cve-2010-0738/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0378/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0376/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0377/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2010-0379/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2011
JBoss, JMX Console, misconfigured DeploymentScanner
This exploit uses the addUrl method in DeploymentScanner module to exploit a misconfigured JBoss JMX Console. It requires the user to edit the $url_cmd to match the war payload url and $url_shell to their reverse shell url. The JSP shell is not the author's and is available everywhere. The author also added a -b param that builds the war container, which requires Java.
Mitigation:
Ensure that the JBoss JMX Console is properly configured and secured.