Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
JBossEAP 信息泄露漏洞
Vulnerability Description
JBoss Enterprise Application PlatformJBoss Enterprise Application Platform是一款企业级应用平台,又称JBossEAP。 JBossEAP4.2.0.CP03之前版本以及4.3.0.CP01之前的4.3.0版本存在信息泄露漏洞。 上述版本允许远程攻击者通过对status servlet的一个请求,例如一个full=true 查询串,获得关于"配置的web内容" 的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A