CVE-2009-0027: Input Validation
The request handler in JBossWS in JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP06 and 4.3 before 4.3.0.CP04 does not properly validate the resource path during a request for a WSDL file with a custom web-service endpoint, which allows remote attackers to read arbitrary XML files via a crafted request.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0027?
CVE-2009-0027 has been assigned a moderate severity level due to the potential for information disclosure.
How do I fix CVE-2009-0027?
To fix CVE-2009-0027, upgrade your JBoss Enterprise Application Platform to versions 4.2.0.CP06 or 4.3.0.CP04 or later.
What types of attacks can exploit CVE-2009-0027?
CVE-2009-0027 can be exploited by remote attackers to read arbitrary files through improperly validated requests for WSDL files.
Which versions of JBoss are impacted by CVE-2009-0027?
CVE-2009-0027 affects JBoss Enterprise Application Platform versions 4.2.0 up to 4.2.0.CP05 and 4.3.0 up to 4.3.0.CP03.
Is CVE-2009-0027 a critical vulnerability?
CVE-2009-0027 is not considered critical but poses a risk that should be addressed to prevent potential data exposure.