JexBoss es una herramienta escrita en python que nos sirve para auditar y explotar vulnerabilidades en JBoss Application Server y otras plataformas Java, Frameworks, Aplicaciones, etc.
Vectores de explotación:
- /admin-console
- tested and working in JBoss versions 5 and 6
 
 - /jmx-console
- tested and working in JBoss versions 4, 5 and 6
 
 - /web-console/Invoker
- tested and working in JBoss versions 4, 5 and 6
 
 - /invoker/JMXInvokerServlet
- tested and working in JBoss versions 4, 5 and 6
 
 - Application Deserialization
- tested and working against multiple java applications, platforms, etc, via HTTP POST Parameters
 
 - Servlet Deserialization
- tested and working against multiple java applications, platforms, etc, via servlets that process serialized objets (e.g. when you see an «Invoker» in a link)
 
 - Apache Struts2 CVE-2017-5638
- tested in Apache Struts 2 applications
 
 - Others