CVE-2008-3273
30Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendepss 47%
probabilidad de explotación
47%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.
Productos afectados
n/a · n/aReferencias
http://marc.info/?l=bugtraq&m=132698550418872&w=2http://rhn.redhat.com/errata/RHSA-2008-0825.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0826.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0827.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0828.htmlhttps://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=457757https://exchange.xforce.ibmcloud.com/vulnerabilities/44235https://jira.jboss.org/jira/browse/JBPAPP-544http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.2.0.cp03/html-single/readme/index.htmlhttp://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.3.0.cp01/html-single/readme/http://www.securityfocus.com/bid/30540http://www.securitytracker.com/id?1020628