AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2007-2975

HIGH · CVSS 7.5 EPSS 2.54%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2007-06-01 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2007-2975
Severity
HIGH
CVSS
7.5
EPSS
2.54%

Original NVD Description

The admin console in Ignite Realtime Openfire 3.3.0 and earlier (formerly Wildfire) does not properly specify a filter mapping in web.xml, which allows remote attackers to gain privileges and execute arbitrary code by accessing functionality that is exposed through DWR, as demonstrated using the downloader.