Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote attackers to bypass the WebRemote annotation restriction and obtain information about arbitrary classes and methods on the server classpath via unspecified vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat Jboss Web Framework Kit 安全绕过漏洞
Vulnerability Description
JBoss Seam 2 Framework是美国红帽(Red Hat)公司的一种企业级Java的应用程序框架,它为所有企业Web应用中的组件提供了一个统一的、易于理解的编程模型。 Jboss Web Framework Kit中使用的JBoss Seam 2 framework 2.3.1及之前的版本中的Jboss Seam Remoting中的InterfaceGenerator处理器中存在安全绕过漏洞。远程攻击者可利用该漏洞绕过WebRemote注释限制,获取服务器类路径下的任意类和方法的信息。
CVSS Information
N/A
Vulnerability Type
N/A