Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2009-0027

Опубликовано: 09 мар. 2009
Источник: ubuntu
Приоритет: low
CVSS2: 5

Описание

The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

4.2.3.GA-1ubuntu1
gutsy

DNE

hardy

not-affected

4.2.2.GA-1
intrepid

not-affected

4.2.2.GA-5ubuntu2
jaunty

not-affected

4.2.3.GA-1
karmic

not-affected

4.2.3.GA-1
upstream

released

4.2.0.CP06, 4.3.0.CP04

Показывать по

Ссылки на источники

5 Medium

CVSS2

Связанные уязвимости

redhat
почти 17 лет назад

The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.

nvd
почти 17 лет назад

The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.

debian
почти 17 лет назад

The request handler in JBossWS in JBoss Enterprise Application Platfor ...

github
больше 3 лет назад

The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.

5 Medium

CVSS2