Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-2595

Опубликовано: 07 июн. 2017
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Single Sign-On 7wildflyUnder investigation
Red Hat JBoss EAP 7FixedRHSA-2017:140907.06.2017
Red Hat JBoss EAP 7FixedRHSA-2017:345613.12.2017
Red Hat JBoss Enterprise Application Platform 6.4FixedRHSA-2017:155120.06.2017
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5hornetqFixedRHSA-2017:155020.06.2017
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5ironjacamar-eap6FixedRHSA-2017:155020.06.2017
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jboss-as-appclientFixedRHSA-2017:155020.06.2017
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jbossas-appclientFixedRHSA-2017:155020.06.2017
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jbossas-bundlesFixedRHSA-2017:155020.06.2017
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jboss-as-cliFixedRHSA-2017:155020.06.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1413028wildfly: Arbitrary file read via path traversal

EPSS

Процентиль: 78%
0.01165
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
nvd
больше 7 лет назад

It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.

CVSS3: 7.7
debian
больше 7 лет назад

It was found that the log file viewer in Red Hat JBoss Enterprise Appl ...

CVSS3: 6.5
github
больше 3 лет назад

It was found that the log file viewer in Red Hat JBoss Enterprise Application 6 and 7 allows arbitrary file read to authenticated user via path traversal.

EPSS

Процентиль: 78%
0.01165
Низкий

7.7 High

CVSS3