In my organization I found servers running JBoss Web/7.0.13.Final and JBoss Web/7.0.12.Final.
I could not find security vulnerabilities for this server's versions, but they seem old to me.
How can I find JBoss Web security vulnerabilities (CVEs, etc.)? I understood that JBoss Web is based on Apache and Tomcat. Does JBoss Web version x.y.z has the same vulnerabilities as Tomcat x.y.z?
Notice that this is not the common general question about finding CVEs for some products, but specifically about JBoss Web. If one can find the CPE for JBoss Web vulnerabilities, or to give a reference to JBoss Web vulnerability - it will help. I could not find such vulnerabilities in NIST and all the classical resources.