5
CVSSv2

CVE-2015-3198

Published: 21/07/2017 Updated: 07/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Undertow module of WildFly 9.x prior to 9.0.0.CR2 and 10.x prior to 10.0.0.Alpha1 allows remote malicious users to obtain the source code of a JSP page via a "/" at the end of a URL.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat jboss wildfly application server 9.0.0

Vendor Advisories

The Undertow module of WildFly 9x before 900CR2 and 10x before 1000Alpha1 allows remote attackers to obtain the source code of a JSP page via a "/" at the end of a URL ...