First published: Tue Mar 10 2020(Updated: )
JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Application Server | >=7.0.0<7.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2012-1094.
The title of the vulnerability is 'JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way which can cause the excluded-contexts list to be mismatched and the root context to be exposed.'
The severity of CVE-2012-1094 is high, with a severity value of 7.5.
The affected software is Redhat Jboss Application Server version between 7.0.0 and 7.1.1.
To fix the vulnerability in JBoss AS 7, you need to upgrade to version 7.1.1 or later.