PT-2009-2742 · Red Hat · Jbossws+1

Marc Schoenefeld

·

Published

2009-03-09

·

Updated

2009-03-21

·

CVE-2009-0027

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions JBoss Enterprise Application Platform versions 4.2.0 through 4.2.0.CP05 JBoss Enterprise Application Platform versions 4.3.0 through 4.3.0.CP03
Description The issue arises from the request handler in JBossWS not properly validating the resource path during a request for a WSDL file with a custom web-service endpoint. This allows remote attackers to read arbitrary XML files via a crafted request.
Recommendations For JBoss Enterprise Application Platform versions 4.2.0 through 4.2.0.CP05, update to version 4.2.0.CP06 or later. For JBoss Enterprise Application Platform versions 4.3.0 through 4.3.0.CP03, update to version 4.3.0.CP04 or later.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0027
RHSA-2009:0346
RHSA-2009:0347
RHSA-2009:0348
RHSA-2009:0349

Affected Products

Red Hat Jboss Enterprise Application Platform
Jbossws