← All CVEs

CVE-2008-3273

medium · 5

JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.

5
CVSS
47.1%
EPSS (exploit prob.)
99th
EPSS percentile
2008-08-10
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
jbossenterprise_application_platform<= 4.2.0.cp03
jbossenterprise_application_platform<= 4.3.0
jbossenterprise_application_platform4.2.0.cp01
jbossenterprise_application_platform4.2.0.cp02

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-3273