First published: Thu Dec 21 2017(Updated: )
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss WildFly Application Server | =9.0.0 | |
Red Hat JBoss WildFly Application Server | =9.0.0-alpha1 | |
Red Hat JBoss WildFly Application Server | =9.0.0-beta1 | |
Red Hat JBoss WildFly Application Server | =9.0.0-beta2 | |
Red Hat JBoss WildFly Application Server | =9.0.0-cr1 | |
Red Hat JBoss WildFly Application Server | =9.0.0-cr2 | |
Red Hat JBoss WildFly Application Server | =9.0.1 | |
Red Hat JBoss WildFly Application Server | =9.0.2 | |
Red Hat JBoss WildFly Application Server | =10.0.0 | |
Red Hat JBoss WildFly Application Server | =10.0.0-alpha1 | |
Red Hat JBoss WildFly Application Server | =10.0.0-alpha2 | |
Red Hat JBoss WildFly Application Server | =10.0.0-alpha3 | |
Red Hat JBoss WildFly Application Server | =10.0.0-alpha4 | |
Red Hat JBoss WildFly Application Server | =10.0.0-alpha5 | |
Red Hat JBoss WildFly Application Server | =10.0.0-alpha6 | |
Red Hat JBoss WildFly Application Server | =10.0.0-beta1 | |
Red Hat JBoss WildFly Application Server | =10.0.0-beta2 | |
Red Hat JBoss WildFly Application Server | =10.0.0-cr1 | |
Red Hat JBoss WildFly Application Server | =10.0.0-cr2 | |
Red Hat JBoss WildFly Application Server | =10.0.0-cr3 | |
Red Hat JBoss WildFly Application Server | =10.0.0-cr4 | |
Red Hat JBoss WildFly Application Server | =10.0.0-cr5 | |
Red Hat JBoss WildFly Application Server | =10.1.0 | |
Red Hat JBoss WildFly Application Server | =10.1.0-cr1 | |
Red Hat JBoss WildFly Application Server | =11.0.0 | |
Red Hat JBoss WildFly Application Server | =11.0.0-alpha1 | |
Red Hat JBoss WildFly Application Server | =11.0.0-beta1 | |
Red Hat JBoss WildFly Application Server | =11.0.0-cr1 | |
JBoss Enterprise Application Platform | =7.1.0 | |
Red Hat Enterprise Linux Server | =6.0 | |
Red Hat Enterprise Linux Server | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1047 has been classified as a medium severity vulnerability due to the potential for information disclosure.
To mitigate CVE-2018-1047, upgrade to a patched version of Red Hat JBoss WildFly Application Server, specifically versions 9.0.1 or later.
Affected versions of Red Hat JBoss WildFly Application Server include 9.0.0, 9.0.0-alpha1, 9.0.0-beta1, 9.0.0-beta2, 9.0.0-cr1, 9.0.0-cr2, and specific versions of 10.0.0.
CVE-2018-1047 is a path traversal vulnerability that could lead to unauthorized access to arbitrary local files on the server.
Yes, CVE-2018-1047 can be exploited remotely, allowing attackers to disclose sensitive information.