CVE-2008-3273
JBoss Enterprise Application Platform (aka JBossEAP or EAP) before 4.2.0.CP03, and 4.3.0 before 4.3.0.CP01, allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string.
- Affected products
- Red Hat Jboss Enterprise Application Platform
- Jboss Enterprise Application Platform
- ≤ 4.2.0.cp03, 4.3.0, 4.2.0.cp01, 4.2.0.cp02
- Fix
- Available
- CVSS 2.0
- 5.0 MEDIUM
- EPSS
- 47.1% (99th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2008-08-10
CVE-2008-3273 at NVD
6 known exploits for CVE-2008-3273
Proof-of-concept code and exploit modules indexed by Sploitus