Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-3273

Опубликовано: 10 авг. 2008
Источник: nvd
CVSS2: 5
EPSS Средний

Описание

JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:jboss:enterprise_application_platform:*:*:*:*:*:*:*:*
Версия до 4.2.0.cp03 (включая)
cpe:2.3:a:jboss:enterprise_application_platform:*:*:*:*:*:*:*:*
Версия до 4.3.0 (включая)
cpe:2.3:a:jboss:enterprise_application_platform:4.2.0.cp01:*:*:*:*:*:*:*
cpe:2.3:a:jboss:enterprise_application_platform:4.2.0.cp02:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.414
Средний

5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 17 лет назад

JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.

redhat
больше 17 лет назад

JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.

debian
больше 17 лет назад

JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2 ...

github
больше 3 лет назад

JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.

EPSS

Процентиль: 97%
0.414
Средний

5 Medium

CVSS2

Дефекты

CWE-264