CVE-2015-3198: Infoleak

Published May 25, 2015
·
Updated

A flaw was reported in the Undertow module of WildFly that leaks the source code of a JSP page when a trailing slash (/) is added to the end of its URL.

This issue did not affect any versions of Red Hat JBoss Enterprise Application Platform because this flaw only affects the Undertow web module; JBoss EAP uses JBoss Web.

Other sources

The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via a "/" at the end of a URL.

MITRE

The Undertow module of WildFly versions 8.1.0.Final, 8.2.0.Final, 9.0.0.CR1 allows remote attackers to obtain the source code of a JSP page via a "/" at the end of a URL.

Affected Software

4 affected componentsFixes available
maven/org.wildfly:wildfly-parent>=8.1.0.Final<=9.0.0.CR1
9.0.0.CR2
redhat Jboss Wildfly Application Server=9.0.0-beta1
redhat Jboss Wildfly Application Server=9.0.0-beta2
redhat Jboss Wildfly Application Server=9.0.0-cr1

Event History

May 25, 2015
Data Sourced
05:48 PM
DescriptionSeverityAffected Software
Jul 21, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 17, 2022
Advisory Published
02:19 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2015-3198?

CVE-2015-3198 has a moderate severity level as it can expose source code inadvertently.

2

How do I fix CVE-2015-3198?

To address CVE-2015-3198, upgrade to WildFly version 9.0.0.CR2 or later.

3

Which versions are affected by CVE-2015-3198?

CVE-2015-3198 affects WildFly versions from 8.1.0.Final up to 9.0.0.CR1.

4

Does CVE-2015-3198 affect Red Hat JBoss Enterprise Application Platform?

No, CVE-2015-3198 does not affect any versions of Red Hat JBoss Enterprise Application Platform.

5

What type of vulnerability is CVE-2015-3198?

CVE-2015-3198 is a source code disclosure vulnerability in the Undertow module of WildFly.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203