Required CVE Record Information
Description
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.
References 13 Total
- rhn.redhat.com: RHSA-2008:0828 vendor-advisory
- rhn.redhat.com: RHSA-2008:0826 vendor-advisory
- marc.info: HPSBMU02736 vendor-advisory
- http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.2.0.cp03/html-single/readme/index.html
- exchange.xforce.ibmcloud.com: jbosseap-statusservlet-info-disclosure(44235) vdb-entry
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=457757
- http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.3.0.cp01/html-single/readme/
- rhn.redhat.com: RHSA-2008:0827 vendor-advisory
- marc.info: SSRT100699 vendor-advisory
- https://jira.jboss.org/jira/browse/JBPAPP-544
- rhn.redhat.com: RHSA-2008:0825 vendor-advisory
- securitytracker.com: 1020628 vdb-entry
- securityfocus.com: 30540 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 13 Total
- rhn.redhat.com: RHSA-2008:0828 vendor-advisoryx_transferred
- rhn.redhat.com: RHSA-2008:0826 vendor-advisoryx_transferred
- marc.info: HPSBMU02736 vendor-advisoryx_transferred
- http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.2.0.cp03/html-single/readme/index.html x_transferred
- exchange.xforce.ibmcloud.com: jbosseap-statusservlet-info-disclosure(44235) vdb-entryx_transferred
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=457757 x_transferred
- http://www.redhat.com/docs/en-US/JBoss_Enterprise_Application_Platform/4.3.0.cp01/html-single/readme/ x_transferred
- rhn.redhat.com: RHSA-2008:0827 vendor-advisoryx_transferred
- marc.info: SSRT100699 vendor-advisoryx_transferred
- https://jira.jboss.org/jira/browse/JBPAPP-544 x_transferred
- rhn.redhat.com: RHSA-2008:0825 vendor-advisoryx_transferred
- securitytracker.com: 1020628 vdb-entryx_transferred
- securityfocus.com: 30540 vdb-entryx_transferred