7.5

CVE-2006-5750

Directory traversal vulnerability in the DeploymentFileRepository class in JBoss Application Server (jbossas) 3.2.4 through 4.0.5 allows remote authenticated users to read or modify arbitrary files, and possibly execute arbitrary code, via unspecified vectors related to the console manager.

Data is provided by the National Vulnerability Database (NVD)
JbossJboss Application Server Version3.2.5_final
JbossJboss Application Server Version3.2.6_final
JbossJboss Application Server Version3.2.7_final
JbossJboss Application Server Version3.2.8.sp1
JbossJboss Application Server Version3.2.8_final
JbossJboss Application Server Version4.0.0_final
JbossJboss Application Server Version4.0.1_final
JbossJboss Application Server Version4.0.1_sp1
JbossJboss Application Server Version4.0.2_final
JbossJboss Application Server Version4.0.3_final
JbossJboss Application Server Version4.0.4.ga
JbossJboss Application Server Version4.0.5.ga
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 22.75% 0.956
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P