5
CVE-2008-3273
- EPSS 29.39%
- Veröffentlicht 10.08.2008 20:41:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle secalert@redhat.com
- Teams Watchlist Login
- Unerledigt Login
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Jboss ≫ Enterprise Application Platform Version <= 4.2.0.cp03
Jboss ≫ Enterprise Application Platform Version <= 4.3.0
Jboss ≫ Enterprise Application Platform Version4.2.0.cp01
Jboss ≫ Enterprise Application Platform Version4.2.0.cp02
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 29.39% | 0.964 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|