CVE-2009-0027

T

he request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp01:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp02:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp03:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp04:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp05:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.2.0:cp06:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp01:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp02:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp03:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:4.3.0:cp04:*:*:*:*:*:*

History

21 Nov 2024, 00:58

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2009-0346.html - Patch () http://rhn.redhat.com/errata/RHSA-2009-0346.html - Patch
References () http://rhn.redhat.com/errata/RHSA-2009-0347.html - Patch () http://rhn.redhat.com/errata/RHSA-2009-0347.html - Patch
References () http://rhn.redhat.com/errata/RHSA-2009-0348.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2009-0348.html - Vendor Advisory
References () http://rhn.redhat.com/errata/RHSA-2009-0349.html - Patch, Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2009-0349.html - Patch, Vendor Advisory
References () http://secunia.com/advisories/34112 - () http://secunia.com/advisories/34112 -
References () http://www.securityfocus.com/bid/34023 - () http://www.securityfocus.com/bid/34023 -
References () http://www.securitytracker.com/id?1021817 - () http://www.securitytracker.com/id?1021817 -
References () https://bugzilla.redhat.com/show_bug.cgi?id=479668 - () https://bugzilla.redhat.com/show_bug.cgi?id=479668 -
References () https://jira.jboss.org/jira/browse/JBPAPP-1548 - () https://jira.jboss.org/jira/browse/JBPAPP-1548 -

Information

Published : 2009-03-09 21:30

Updated : 2025-04-09 00:30


NVD link : CVE-2009-0027

Mitre link : CVE-2009-0027

CVE.ORG link : CVE-2009-0027


JSON object : View

CWE
CWE-20

Improper Input Validation