Логотип exploitDog
bind:CVE-2008-3519
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2008-3519

Количество 4

Количество 4

redhat логотип

CVE-2008-3519

почти 17 лет назад

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

EPSS: Низкий
nvd логотип

CVE-2008-3519

почти 17 лет назад

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-3519

почти 17 лет назад

The default configuration of the JBossAs component in Red Hat JBoss En ...

CVSS2: 4.3
EPSS: Низкий
github логотип

GHSA-62gp-x3rq-2r53

больше 3 лет назад

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2008-3519

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-3519

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

CVSS2: 4.3
1%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-3519

The default configuration of the JBossAs component in Red Hat JBoss En ...

CVSS2: 4.3
1%
Низкий
почти 17 лет назад
github логотип
GHSA-62gp-x3rq-2r53

The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу