Логотип exploitDog
bind:CVE-2008-3519
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2008-3519

Количество 4

Количество 4

redhat логотип

CVE-2008-3519

больше 17 лет назад

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

EPSS: Низкий
nvd логотип

CVE-2008-3519

больше 17 лет назад

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-3519

больше 17 лет назад

The default configuration of the JBossAs component in Red Hat JBoss En ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-62gp-x3rq-2r53

почти 4 года назад

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2008-3519

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-3519

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-3519

The default configuration of the JBossAs component in Red Hat JBoss En ...

CVSS2: 4.3
1%
Низкий
больше 17 лет назад
github логотип
GHSA-62gp-x3rq-2r53

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу