CVE-2009-0027

Impact:
Moderate
Public Date:
2009-03-06
Bugzilla:
479668: CVE-2009-0027 JBoss EAP unprivileged local xml file access

The MITRE CVE dictionary describes this issue as:

The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.

Find out more about CVE-2009-0027 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 5
Base Metrics AV:N/AC:L/Au:N/C:P/I:N/A:N
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 4 AS RHSA-2009:0347 2009-03-06
Red Hat JBoss Enterprise Application Platform 4.2.0 for RHEL 4 AS RHSA-2009:0346 2009-03-06
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 5 Server RHSA-2009:0349 2009-03-06
Red Hat JBoss Enterprise Application Platform 4.2.0 for RHEL 5 Server RHSA-2009:0348 2009-03-06

Last Modified

CVE description copyright © 2017, The MITRE Corporation

Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.