Описание
Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malformed request.
Ссылки
- Patch
- PatchVendor Advisory
- Patch
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:sun:java_system_application_server:8.1:*:linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.1:*:sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.1:*:windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.1:*:x86:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:linux:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:sparc:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:windows:*:*:*:*:*
cpe:2.3:a:sun:java_system_application_server:8.2:*:x86:*:*:*:*:*
EPSS
Процентиль: 64%
0.00467
Низкий
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
github
почти 4 года назад
Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malformed request.
EPSS
Процентиль: 64%
0.00467
Низкий
5 Medium
CVSS2
Дефекты
CWE-200