5
CVSSv2

CVE-2009-0027

Published: 09/03/2009 Updated: 21/03/2009
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 prior to 4.2.0.CP06 and 4.3 prior to 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote malicious users to read arbitrary XML files via a crafted request.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss enterprise application platform 4.3.0

redhat jboss enterprise application platform 4.2.0

Vendor Advisories

Synopsis Moderate: JBoss Enterprise Application Platform 430CP04 update Type/Severity Security Advisory: Moderate Topic Updated JBoss Enterprise Application Platform (JBoss EAP) 43 packages thatfix various issues are now available for Red Hat Enterprise Linux 5 asJBEAP 430CP04This update has been rat ...