Jboss EAP(企业应用平台)是J2EE应用的中间件平台。undertow是其中的一个用Java编写的Web服务器。AJP connector是其中的一个AJP(定向包协议)连接器。 Jboss EAP 7.1.0.GA版本中undertow的AJP connector存在安全漏洞,该漏洞源于程序没有使用ALLOW_ENCODED_SLASH选项。攻击者可利用该漏洞获取本地任意文件的信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat, Inc. | undertow as shipped in Jboss EAP 7.1.0.GA | 7.1.0.GA | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2018-1047 | Wildfly 输入验证错误漏洞 | |
| CVE-2017-15135 | 389-ds-base 授权问题漏洞 |
No comments yet