Описание
A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on the server it is deployed on. The highest threat from this vulnerability is to data confidentiality.
Ссылки
- Issue TrackingVendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.0.39 (исключая)
Одно из
cpe:2.3:a:redhat:jboss-ejb-client:*:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00171
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-200
CWE-200
Связанные уязвимости
CVSS3: 4.3
redhat
больше 4 лет назад
A flaw was found in wildfly. The JBoss EJB client has publicly accessible privileged actions which may lead to information disclosure on the server it is deployed on. The highest threat from this vulnerability is to data confidentiality.
CVSS3: 4.3
debian
около 4 лет назад
A flaw was found in wildfly. The JBoss EJB client has publicly accessi ...
CVSS3: 4.3
github
около 3 лет назад
JBoss EJB Client information disclosure vulnerability
EPSS
Процентиль: 39%
0.00171
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-200
CWE-200