5
CVE-2008-3273
- EPSS 29.39%
- Published 10.08.2008 20:41:00
- Last modified 09.04.2025 00:30:58
- Source secalert@redhat.com
- Teams watchlist Login
- Open Login
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.
Data is provided by the National Vulnerability Database (NVD)
Jboss ≫ Enterprise Application Platform Version <= 4.2.0.cp03
Jboss ≫ Enterprise Application Platform Version <= 4.3.0
Jboss ≫ Enterprise Application Platform Version4.2.0.cp01
Jboss ≫ Enterprise Application Platform Version4.2.0.cp02
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 29.39% | 0.964 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|